ZeroHour

CVE-2016-3081

PoC
CVSS 3.0
8.1 high
EPSS
93%p100
Published
()
Modified
Description

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

Vendors
apacheoracle
Products
struts, siebel e-billing
Weakness
CWE-77
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news