Opensymphony / Xwork
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2011-2088 | struts: Allows remote attackers to obtain potentially sensitive information via vectors involving an s:submit element | MEDIUM | 5.0 | May 13, 2011 |
| CVE-2011-1772 | struts: Multiple XSS flaws in XWork | LOW | 2.6 | May 13, 2011 |
| CVE-2008-6504 | Struts2/WebWorks/XWork: ParameterInterceptors bypass allows OGNL statement execution | MEDIUM | 5.0 | Mar 23, 2009 |
| CVE-2007-4556 | Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Gra… | MEDIUM | 6.8 | Aug 28, 2007 |
Showing 1 to 4 of 4 CVEs