← All CVEs

CVE-2007-4556

medium · 6.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

6.8
CVSS
25.7%
EPSS (exploit prob.)
98th
EPSS percentile
2007-08-28
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
opensymphonyxwork< 1.2.3
opensymphonyxwork>= 2.0.0, <= 2.0.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-4556