CVEs Blog | G5 Cyber Security

CVE-2016-3082 – XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3082

Reference (s):

Exit mobile version