296,746
Total vulnerabilities in the database
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
| Software | From | Fixed in |
|---|---|---|
| apache / struts | 2.0.0 | 2.3.14.3 |
org.apache.struts / struts2-core
|
- | 2.3.14.3 |