- Apache Struts2 is a web framework for creating Java web applications. It is using the OpenSymphony XWork and OGNL libraries. By default, XWork's ParametersInterceptor treats parameter names provided to actions as OGNL expressions. A OGNL (Object Graph Navigation Language) expression is a limited language similar to Java that is tokenized and parsed by the OGNL parser which invokes appropriate Java methods. Under certain circumstances it's possible to send custom OGNL statements and execute malicious Java code.
- Upgrade to Struts version 220.127.116.11
- WordPress Plugin is_human() 'type' Parameter Remote Command Injection (1.4.2)
- WordPress Plugin WordPress Download Manager Multiple Vulnerabilities (2.8.7)
- Apache Log4j socket receiver deserialization vulnerability
- WordPress Plugin eCommerce Shopping Cart by WP EasyCart Multiple Security Bypass Vulnerabilities (3.0.20)