Top 10 winner
Apache Struts ClassLoader Manipulation Remote Code Execution
S2-020 - Apache Struts 2 Documentation
The Struts S2-020 bulletin covers two issues fixed in 2.3.16.1: Commons FileUpload 1.3 allows denial of service, and ParametersInterceptor accepts a class parameter mapped to getClass(), letting a remote attacker manipulate the ClassLoader. The advised remedies are upgrading the library and excluding class from request parameters.
Record
- Document
- S2-020 - Apache Struts 2 Documentation
- Researcher
- Lukasz Lenart
- Published by
- cwiki.apache.org
- Topic
- Server
In the archive
Related sources
- CVE-2014-0094 Apache Struts ClassLoader Manipulation Remote Code Execution
- Struts classloader exploit
Tags
This page is the archive's own catalogue record. The research is the work of Lukasz Lenart, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .