CVE-2013-2248
medium · 5.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
5.8
CVSS
94.7%
EPSS (exploit prob.)
100th
EPSS percentile
2013-07-20
Published
AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | struts | 2.0.0 |
| apache | struts | 2.0.1 |
| apache | struts | 2.0.2 |
| apache | struts | 2.0.3 |
| apache | struts | 2.0.4 |
| apache | struts | 2.0.5 |
| apache | struts | 2.0.6 |
| apache | struts | 2.0.7 |
| apache | struts | 2.0.8 |
| apache | struts | 2.0.9 |
| apache | struts | 2.0.10 |
| apache | struts | 2.0.11 |
| apache | struts | 2.0.11.1 |
| apache | struts | 2.0.11.2 |
| apache | struts | 2.0.12 |
| apache | struts | 2.0.13 |
| apache | struts | 2.0.14 |
| apache | struts | 2.1.0 |
| apache | struts | 2.1.1 |
| apache | struts | 2.1.2 |
| apache | struts | 2.1.3 |
| apache | struts | 2.1.4 |
| apache | struts | 2.1.5 |
| apache | struts | 2.1.6 |
| apache | struts | 2.1.8 |
| apache | struts | 2.1.8.1 |
| apache | struts | 2.2.1 |
| apache | struts | 2.2.1.1 |
| apache | struts | 2.2.3 |
| apache | struts | 2.2.3.1 |
| apache | struts | 2.3.1 |
| apache | struts | 2.3.1.1 |
| apache | struts | 2.3.1.2 |
| apache | struts | 2.3.3 |
| apache | struts | 2.3.4 |
| apache | struts | 2.3.4.1 |
| apache | struts | 2.3.7 |
| apache | struts | 2.3.8 |
| apache | struts | 2.3.12 |
| apache | struts | 2.3.14 |
Check a specific version with /api/v1/cve/match.
References
- http://struts.apache.org/release/2.3.x/docs/s2-017.html
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://www.securityfocus.com/bid/61196
- http://www.securityfocus.com/bid/64758
- http://struts.apache.org/release/2.3.x/docs/s2-017.html
- http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://www.securityfocus.com/bid/61196
- http://www.securityfocus.com/bid/64758
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-2248