Total vulnerabilities in the database
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Software | From | Fixed in |
---|---|---|
apache / struts | 2.0.0 | 2.3.16.1 |
![]() |
- | 2.3.16.2 |