← All CVEs

CVE-2016-3081

high · 8.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

8.1
CVSS
93.4%
EPSS (exploit prob.)
100th
EPSS percentile
2016-04-26
Published

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
apachestruts2.0.0
apachestruts2.0.1
apachestruts2.0.2
apachestruts2.0.3
apachestruts2.0.4
apachestruts2.0.5
apachestruts2.0.6
apachestruts2.0.7
apachestruts2.0.8
apachestruts2.0.9
apachestruts2.0.10
apachestruts2.0.11
apachestruts2.0.11.1
apachestruts2.0.11.2
apachestruts2.0.12
apachestruts2.0.13
apachestruts2.0.14
apachestruts2.1.0
apachestruts2.1.1
apachestruts2.1.2
apachestruts2.1.3
apachestruts2.1.4
apachestruts2.1.5
apachestruts2.1.6
apachestruts2.1.8
apachestruts2.1.8.1
apachestruts2.2.1
apachestruts2.2.1.1
apachestruts2.2.3
apachestruts2.2.3.1
apachestruts2.3.1
apachestruts2.3.1.1
apachestruts2.3.1.2
apachestruts2.3.3
apachestruts2.3.4
apachestruts2.3.4.1
apachestruts2.3.7
apachestruts2.3.8
apachestruts2.3.12
apachestruts2.3.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-3081