Java Mailing List Archive

http://www.gg3721.com/

Home » Struts Users Mailing List »

Struts2 remote commands execution

Meder Kydyraliev

2010-07-10

Replies: Find Java Web Hosting

Author LoginPost Reply
There's a critical remote commands execution vulnerability in XWork(used by
Struts2), which fixed in 2.2.0, which isn't released yet but can be
downloaded here: http://people.apache.org/builds/struts/2.2.0/

More details about this vulnerability can be found here:
http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html

Meder
©2008 gg3721.com - Jax Systems, LLC, U.S.A.