Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Struts Multiple Directory Traversal Vulnerabilities

Struts is prone to multiple directory-traversal vulnerabilities because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit these issues using directory-traversal strings ('../') to download arbitrary files with the privileges of the webserver process. Information obtained may aid in further attacks.

Versions prior to Struts 2.0.12 are vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus