Total vulnerabilities in the database
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
Software | From | Fixed in |
---|---|---|
apache / struts | 2.0.0 | 2.3.14.3 |
![]() |
- | 2.3.14.3 |