296,746
Total vulnerabilities in the database
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
| Software | From | Fixed in |
|---|---|---|
| apache / struts | 2.3.28 | 2.3.28.x |
| apache / struts | 2.3.20.2 | 2.3.20.2.x |
| apache / struts | 2.3.25 | 2.3.25.x |
| apache / struts | 2.3.24.2 | 2.3.24.2.x |
| apache / struts | 2.3.24.1 | 2.3.24.1.x |
| apache / struts | 2.3.22 | 2.3.22.x |
| apache / struts | 2.3.23 | 2.3.23.x |
| apache / struts | 2.3.24.3 | 2.3.24.3.x |
| apache / struts | 2.3.29 | 2.3.29.x |
| apache / struts | 2.3.20.1 | 2.3.20.1.x |
| apache / struts | 2.3.30 | 2.3.30.x |
| apache / struts | 2.3.24 | 2.3.24.x |
| apache / struts | 2.3.28.1 | 2.3.28.1.x |
| apache / struts | 2.3.20.3 | 2.3.20.3.x |
| apache / struts | 2.3.26 | 2.3.26.x |
| apache / struts | 2.3.27 | 2.3.27.x |
| apache / struts | 2.3.21 | 2.3.21.x |
| apache / struts | 2.3.20 | 2.3.20.x |
org.apache.struts / struts2-core
|
2.3.0 | 2.3.31 |
org.apache.struts / struts2-core
|
2.5.0 | 2.5.5 |