Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2006-0161.html | vendor advisory |
http://www.vupen.com/english/advisories/2005/2525 | vdb entry |
http://www.osvdb.org/21021 | vdb entry |
http://www.securityfocus.com/bid/15512 | exploit vdb entry patch |
http://www.hacktics.com/AdvStrutsNov05.html | exploit patch vendor advisory |
http://www.securityfocus.com/archive/1/417296/30/0/threaded | mailing list |
http://www.redhat.com/support/errata/RHSA-2006-0157.html | vendor advisory |
http://securitytracker.com/id?1015257 | vdb entry |
http://securityreason.com/securityalert/197 | third party advisory |
http://secunia.com/advisories/17677 | third party advisory |
http://secunia.com/advisories/18341 | third party advisory |
https://lists.apache.org/thread.html/r02c2d634fa74209d941c90f9a4cd36a6f12366ca65f9b90446ff2de3%40%3Cissues.struts.apache.org%3E | mailing list |
https://lists.apache.org/thread.html/rf482c101a88445d73cc2e89dbf7f16ae00a4aa79a544a1e72b2326db%40%3Cissues.struts.apache.org%3E | mailing list |