CVE-2011-3923

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_enterprise_web_server:1.0.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:08

Type Values Removed Values Added
References (MISC) https://security-tracker.debian.org/tracker/CVE-2011-3923 - Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2011-3923 -
References (MISC) http://seclists.org/fulldisclosure/2014/Jul/38 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2014/Jul/38 -
References (MISC) http://www.securitytracker.com/id?1026575 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1026575 -
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3923 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3923 -
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/72585 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/72585 -
References (EXPLOIT-DB) http://www.exploit-db.com/exploits/24874 - Exploit, Third Party Advisory, VDB Entry () http://www.exploit-db.com/exploits/24874 -
References (BID) http://www.securityfocus.com/bid/51628 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/51628 -

Information

Published : 2019-11-01 14:15

Updated : 2023-12-10 13:13


NVD link : CVE-2011-3923

Mitre link : CVE-2011-3923

CVE.ORG link : CVE-2011-3923


JSON object : View

Products Affected

redhat

  • jboss_enterprise_web_server

apache

  • struts
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource