CVE-2012-0394

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html - Broken Link () http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html - Broken Link
References () http://struts.apache.org/2.x/docs/s2-008.html - Vendor Advisory () http://struts.apache.org/2.x/docs/s2-008.html - Vendor Advisory
References () http://struts.apache.org/2.x/docs/version-notes-2311.html - Release Notes, Vendor Advisory () http://struts.apache.org/2.x/docs/version-notes-2311.html - Release Notes, Vendor Advisory
References () http://www.exploit-db.com/exploits/18329 - Exploit, Third Party Advisory, VDB Entry () http://www.exploit-db.com/exploits/18329 - Exploit, Third Party Advisory, VDB Entry
References () http://www.exploit-db.com/exploits/31434 - Exploit, Third Party Advisory, VDB Entry () http://www.exploit-db.com/exploits/31434 - Exploit, Third Party Advisory, VDB Entry
References () http://www.osvdb.org/78276 - Broken Link () http://www.osvdb.org/78276 - Broken Link
References () https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt - Broken Link () https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt - Broken Link

07 Nov 2023, 02:09

Type Values Removed Values Added
Summary ** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself." The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.

Information

Published : 2012-01-08 15:55

Updated : 2025-04-11 00:51


NVD link : CVE-2012-0394

Mitre link : CVE-2012-0394

CVE.ORG link : CVE-2012-0394


JSON object : View

Products Affected

apache

  • struts
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')