296,733
Total vulnerabilities in the database
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from applications that do not use the isCancelled check.
| Software | From | Fixed in |
|---|---|---|
| apache / struts | - | 1.2.8.x |
struts / struts
|
- | 1.2.9 |