← All CVEs

CVE-2016-3082

critical · 9.8

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.

9.8
CVSS
19.2%
EPSS (exploit prob.)
97th
EPSS percentile
2016-04-26
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachestruts2.0.0
apachestruts2.0.1
apachestruts2.0.2
apachestruts2.0.3
apachestruts2.0.4
apachestruts2.0.5
apachestruts2.0.6
apachestruts2.0.7
apachestruts2.0.8
apachestruts2.0.9
apachestruts2.0.10
apachestruts2.0.11
apachestruts2.0.11.1
apachestruts2.0.11.2
apachestruts2.0.12
apachestruts2.0.13
apachestruts2.0.14
apachestruts2.1.0
apachestruts2.1.1
apachestruts2.1.2
apachestruts2.1.3
apachestruts2.1.4
apachestruts2.1.5
apachestruts2.1.6
apachestruts2.1.8
apachestruts2.1.8.1
apachestruts2.2.1
apachestruts2.2.1.1
apachestruts2.2.3
apachestruts2.2.3.1
apachestruts2.3.1
apachestruts2.3.1.1
apachestruts2.3.1.2
apachestruts2.3.3
apachestruts2.3.4
apachestruts2.3.4.1
apachestruts2.3.7
apachestruts2.3.8
apachestruts2.3.12
apachestruts2.3.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-3082