Apache Struts I18NInterceptor cross-site scripting (CVE-2016-2162)
Apache Struts I18NInterceptor cross-site scripting (CVE-2016-2162)
Release date:
Updated on:
Affected Systems:
Apache Struts 2.0.0 - 2.3.24.1
Description:
CVE (CAN) ID: CVE-2016-2162
Struts2 is an extensible framework for building enterprise-level Jave Web applications.
Struts 2.0.0-2.3.24.1 I18NInterceptor has a security vulnerability that allows unauthenticated remote attackers to execute cross-site scripting attacks and execute arbitrary scripts or HTML in user sessions. The I18NInterceptor component is mainly used for language conversion within the conversion framework or applications built on it.
<* Source: Paolo Perliti paolo dot perliti
Link: http://struts.apache.org/docs/s2-030.html
*>
Suggestion:
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (s2-030) and patches for this:
S2-030: Possible XSS vulnerability in I18NInterceptor
Link: http://struts.apache.org/docs/s2-030.html
Patch download: http://struts.apache.org/docs/version-notes-2326.html
Struts2 Study Notes-Value Stack and OGNL expressions
Upload struts2 files (Save As BLOB)
Getting started instance of Struts2
Implement the ModelDriven interface in Struts2
Struts2 file downloading garbled
Struts2 Spring integration methods and principles
Several knowledge points about Struts2 annotation Mode
Struts details: click here
Struts: click here
This article permanently updates the link address: