Apache Struts2 ParametersInterceptor Remote Command Execution
| TSL ID | FSC20100713-06 |
| CVE ID(s) | CVE-2010-1870 |
| Severity | Critical |
| Description | A command execution vulnerability exists in the web application framework Apache Struts2. The vulnerability is due to insufficient input validation in the ParametersInterceptor component when parsing incoming HTTP requests. A remote attacker can leverage this vulnerability by sending a crafted HTTP request to a target system. In an attack scenario, where arbitrary commands are executed on the target machine, the malicious command will be executed within the security context of the target service. The vendor, Apache, has provided a source patch for this vulnerability: |
| Affected Products |
|
| CVSS Score |
Base 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P):
|