CVE-2011-2087
published 2011-05-13CVE-2011-2087: Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
6.13%
92.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
struts: Multiple XSS flaws in component handlers in javatemplates plug-in
vendor_redhat·2011-03-23·CVSS 4.3
CVE-2011-2087 [MEDIUM] CWE-79 struts: Multiple XSS flaws in component handlers in javatemplates plug-in
struts: Multiple XSS flaws in component handlers in javatemplates plug-in
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a .action URI, related to improper handling of value attributes in (1) FileHandler.java, (2) HiddenHandler.java, (3) PasswordHandler.java, (4) RadioHandler.java, (5) ResetHandler.java, (6) SelectHandler.java, (7) SubmitHandler.java, and (8) TextFieldHandler.java.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2
OSV
Apache Struts Multiple XSS Vulnerabilities
osv·2022-05-17
CVE-2011-2087 [MEDIUM] Apache Struts Multiple XSS Vulnerabilities
Apache Struts Multiple XSS Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a `.action` URI, related to improper handling of value attributes in
1. `FileHandler.java`
1. `HiddenHandler.java`
1. `PasswordHandler.java`
1. `RadioHandler.java`
1. `ResetHandler.java`
1. `SelectHandler.java`
1. `SubmitHandler.java`
1. `TextFieldHandler.java`
GHSA
Apache Struts Multiple XSS Vulnerabilities
ghsa·2022-05-17
CVE-2011-2087 [MEDIUM] CWE-79 Apache Struts Multiple XSS Vulnerabilities
Apache Struts Multiple XSS Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in component handlers in the javatemplates (aka Java Templates) plugin in Apache Struts 2.x before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via an arbitrary parameter value to a `.action` URI, related to improper handling of value attributes in
1. `FileHandler.java`
1. `HiddenHandler.java`
1. `PasswordHandler.java`
1. `RadioHandler.java`
1. `ResetHandler.java`
1. `SelectHandler.java`
1. `SubmitHandler.java`
1. `TextFieldHandler.java`
No detection rules found.
No public exploits indexed.
http://struts.apache.org/2.2.3/docs/version-notes-223.htmlhttp://www.vupen.com/english/advisories/2011/1198https://issues.apache.org/jira/browse/WW-3597https://issues.apache.org/jira/browse/WW-3608http://struts.apache.org/2.2.3/docs/version-notes-223.htmlhttp://www.vupen.com/english/advisories/2011/1198https://issues.apache.org/jira/browse/WW-3597https://issues.apache.org/jira/browse/WW-3608
2011-05-13
Published