CVE-2009-1275
Last modified
CVE-2009-1275 is a vulnerability of currently unknown severity. Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.. EPSS estimates a 2.81% chance of exploitation in the next 30 days.
Description
Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tiles | 2.1.0 |
| Apache | Tiles | 2.1.1 |
References
- https://issues.apache.org/struts/browse/TILES-351Vendor Advisory
- https://issues.apache.org/struts/browse/TILES-351Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1275?
How severe is CVE-2009-1275?
How do I fix CVE-2009-1275?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1269Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 …
- CVE-2009-1270libclamav/untar.c in ClamAV before 0.95 allows remote attack…
- CVE-2009-1271The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2…
- CVE-2009-1272The php_zip_make_relative_path function in php_zip.c in PHP …
- CVE-2009-1273pam_ssh 1.92 and possibly other versions, as used when PAM i…
- CVE-2009-1274Integer overflow in the qt_error parse_trak_atom function in…
- CVE-2009-1276XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_10…
- CVE-2009-1277SQL injection vulnerability in index.php in Gravity Board X …
- CVE-2009-1278Static code injection vulnerability in forms/ajax/configure.…
- CVE-2009-1279Multiple cross-site scripting (XSS) vulnerabilities in Jooml…
- CVE-2009-1280Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2009-1281Cross-site scripting (XSS) vulnerability in glFusion before …
Are you affected by CVE-2009-1275?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
