CVE-2011-1772
Last modified
CVE-2011-1772 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.. EPSS estimates a 34.11% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Struts | 2.0.0 |
| Apache | Struts | 2.0.1 |
| Apache | Struts | 2.0.2 |
| Apache | Struts | 2.0.3 |
| Apache | Struts | 2.0.4 |
| Apache | Struts | 2.0.5 |
| Apache | Struts | 2.0.6 |
| Apache | Struts | 2.0.7 |
| Apache | Struts | 2.0.8 |
| Apache | Struts | 2.0.9 |
| Apache | Struts | 2.0.10 |
| Apache | Struts | 2.0.11 |
| Apache | Struts | 2.0.11.1 |
| Apache | Struts | 2.0.11.2 |
| Apache | Struts | 2.0.12 |
| Apache | Struts | 2.0.13 |
| Apache | Struts | 2.0.14 |
| Apache | Struts | 2.1.0 |
| Apache | Struts | 2.1.1 |
| Apache | Struts | 2.1.2 |
| Apache | Struts | 2.1.3 |
| Apache | Struts | 2.1.4 |
| Apache | Struts | 2.1.5 |
| Apache | Struts | 2.1.6 |
| Apache | Struts | 2.1.8 |
| Apache | Struts | 2.1.8.1 |
| Apache | Struts | 2.2.1 |
| Apache | Struts | 2.2.1.1 |
| Opensymphony | Webwork | All versions |
| Opensymphony | Xwork | All versions |
References
- http://struts.apache.org/2.x/docs/s2-006.htmlExploit, Patch
- http://www.vupen.com/english/advisories/2011/1198Vendor Advisory
- http://struts.apache.org/2.x/docs/s2-006.htmlExploit, Patch
- http://www.vupen.com/english/advisories/2011/1198Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1772?
How severe is CVE-2011-1772?
How do I fix CVE-2011-1772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-1766includes/User.php in MediaWiki before 1.16.5, when wgBlockDi…
- CVE-2011-1767net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip…
- CVE-2011-1768The tunnels implementation in the Linux kernel before 2.6.34…
- CVE-2011-1769SystemTap 1.4 and earlier, when unprivileged (aka stapusr) m…
- CVE-2011-1770Integer underflow in the dccp_parse_options function (net/dc…7.5
- CVE-2011-1771The cifs_close function in fs/cifs/file.c in the Linux kerne…7.8
- CVE-2011-1773virt-v2v before 0.8.4 does not preserve the VNC console pass…
- CVE-2011-1774WebKit in Apple Safari before 5.0.6 has improper libxslt sec…
- CVE-2011-1775The CSecurityTLS::processMsg function in common/rfb/CSecurit…
- CVE-2011-1776The is_gpt_valid function in fs/partitions/efi.c in the Linu…6.1
- CVE-2011-1777Multiple buffer overflows in the (1) heap_add_entry and (2) …
- CVE-2011-1778Buffer overflow in libarchive through 2.8.5 allows remote at…
Are you affected by CVE-2011-1772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
