- Apache Struts2 is a web framework for creating Java web applications. It is using the OpenSymphony XWork and OGNL libraries. By default, XWork's ParametersInterceptor treats parameter names provided to actions as OGNL expressions. A OGNL (Object Graph Navigation Language) expression is a limited language similar to Java that is tokenized and parsed by the OGNL parser which invokes appropriate Java methods. Under certain circumstances it's possible to send custom OGNL statements and execute malicious Java code.
- Upgrade to Struts version 22.214.171.124
- WordPress Plugin Custom Login Page Customizer-LoginPress Multiple Vulnerabilities (1.1.13)
- WordPress caching plugins PHP code execution
- WordPress Plugin Contact Form 7 Privilege Escalation (5.0.3)
- Multiple vulnerabilities reported in Parallels Plesk Sitebuilder
- WordPress Plugin OptinMonster-Best WordPress Popup and Lead Generation Security Bypass (126.96.36.199)