CVE-2011-3923
critical · 9.8Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
9.8
CVSS
89.5%
EPSS (exploit prob.)
100th
EPSS percentile
2019-11-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-732
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | struts | >= 2.0.0, < 2.3.1.2 |
| redhat | jboss_enterprise_web_server | 1.0.0 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2014/Jul/38
- http://www.exploit-db.com/exploits/24874
- http://www.securityfocus.com/bid/51628
- http://www.securitytracker.com/id?1026575
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72585
- https://security-tracker.debian.org/tracker/CVE-2011-3923
- http://seclists.org/fulldisclosure/2014/Jul/38
- http://www.exploit-db.com/exploits/24874
- http://www.securityfocus.com/bid/51628
- http://www.securitytracker.com/id?1026575
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3923
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72585
- https://security-tracker.debian.org/tracker/CVE-2011-3923
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-3923