CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor cha...
Description
Apache Struts's DebuggingInterceptor component allows remote code execution in developer mode
CVSS Vector Breakdown
AV:NAccess VectorAC:MAccess ComplexityAu:NAuthenticationC:PConfidentialityI:PIntegrityA:PAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2012-0394 and every CVE in our database. Create a free account — no credit card required.
Create Free Account