Learn Search

Search across all Learn content

← Back to Security Research

Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilities

SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting in Apache Struts Vulnerabilities. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials or i...

Jan 31, 2012By Veerendra GG1 min read

SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting in Apache Struts Vulnerabilities. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks.

More information can be found here.

CVE Info : CVE-2012-1006 , CVE-2012-1007

Welcome any feedback or suggestion.

Cheers!
SecPod Research Team

Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilitie | SecPod