Korean
<< Back
VID 27110
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://seclists.org/fulldisclosure/2013/Oct/244

* Platforms Affected:
Apache Struts 2.3.15.3
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Struts (2.3.15.3 later), available from the Apache Struts Web page at
https://struts.apache.org/download.cgi
Related URL CVE-2013-6348 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)