Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-6504


ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.


Published

2009-03-23T14:19:12.407

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opensymphony xwork 2.0.0 Yes
Application opensymphony xwork 2.0.1 Yes
Application opensymphony xwork 2.0.2 Yes
Application opensymphony xwork 2.0.3 Yes
Application opensymphony xwork 2.0.4 Yes
Application opensymphony xwork 2.0.5 Yes
Application opensymphony xwork 2.1.0 Yes
Application opensymphony xwork 2.1.1 Yes
Application apache struts 2.0.0 Yes
Application apache struts 2.0.2 Yes
Application apache struts 2.0.3 Yes
Application apache struts 2.0.4 Yes
Application apache struts 2.0.5 Yes
Application apache struts 2.0.6 Yes
Application apache struts 2.0.7 Yes
Application apache struts 2.0.8 Yes
Application apache struts 2.0.9 Yes
Application apache struts 2.0.11 Yes
Application apache struts 2.0.11.1 Yes
Application apache struts 2.0.11.2 Yes

References