[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2014:095 -- Mandriva struts

ID: oval:org.secpod.oval:def:1300305Date: (C)2014-06-11   (M)2023-12-07
Class: PATCHFamily: unix




Updated struts packages fix security vulnerability: It was found that the Struts 1 ActionForm object allowed access to the 'class' parameter, which is directly mapped to the getClass method. A remote attacker could use this flaw to manipulate the ClassLoader used by an application server running Struts 1. This could lead to remote code execution under certain conditions .

Platform:
Mandriva Enterprise Server 5.2
Product:
struts
Reference:
MDVSA-2014:095
CVE-2014-0114
CVE    1
CVE-2014-0114
CPE    19
cpe:/a:apache:struts:1.0
cpe:/a:apache:struts:1.2.8
cpe:/a:apache:struts:1.1
cpe:/a:apache:struts:1.1:rc1
...

© SecPod Technologies