Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97016
HistoryDec 12, 2023 - 12:00 a.m.

Apache Struts Directory Traversal Vulnerability

2023-12-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
38
apache struts
directory traversal
vulnerability
code execution
file upload

AI Score

7.6

Confidence

Low

EPSS

0.09

Percentile

94.6%

Apache Struts is the United States Apache (Apache) Foundation, an open source project , is a set of open source MVC framework for creating enterprise-class Java Web applications , mainly provides two versions of the framework products , Struts 1 and Struts 2. Apache Struts suffers from a directory traversal vulnerability due to a flaw in the Struts framework’s logic for uploading files, which can be exploited by an attacker to execute remote code by constructing a file upload parameter and traversing the file.