Struts is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Apache Software Foundation Struts 1.2.7
+ RedHat Application Server 3WS
+ RedHat Application Server 3ES
+ RedHat Application Server 3AS
Red Hat has released advisory RHSA-2006:0157-01 along with fixes to address this issue for Red Hat Application Server 3. Please see the referenced advisory for more information.
The vendor has addressed this issue in version 1.2.8:
Apache Software Foundation Struts 1.2.7
Apache Software Foundation struts-1.2.8-src.tar.gz
<a href="http://struts.apache.org/download.cgi" target="_blank">http://struts.apache.org/download.cgi</a>
暂无评论