Skip to main content

Vendor/product archive

opensymphony / xwork CVEs

Beta · best-effort

4 CVEs tagged to opensymphony / xwork0 Critical, 0 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2008-6504

Published Mar 23, 2009

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) refer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4556

Published Aug 28, 2007

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Langua…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1