CVE-2013-2251

Apache Struts Improper Input Validation Vulnerability

9.8
CVSS 3.1
100.0 %
EPSS (current)
2022-03-25
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Apache / Struts

Published: 2013-07-20 · Due (CISA): 2022-04-15

CWE: CWE-74 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2013/CVE-2013-2251.yamlApache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution–
metasploitexploit/multi/http/struts_default_action_mapperexploit/multi/http/struts_default_action_mapper2013-07-02
exploitdb27135Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)2013-07-27
exploitdb44583Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection2014-01-14

References only — no downloads or instructions.

Sources