CVE-2013-2251

KEV
Published: Lug 20, 2013 Last Modified: Ott 22, 2025
ExploitDB:
Other exploit source:
Google Dorks: Google Dorks
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 9,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete

Description

AI Translation Available

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,9433
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

View on Exploit-DB GHDB vulnerable servers
Google Query: https://www.google.com/search?q=inurl%3A%22struts%22+filetype%3Aaction
Author: anonymous Date: 2013-11-25
74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Other Integrity Non-Repudiation
Potential Impacts:
Read Application Data Bypass Protection Mechanism Alter Execution Logic Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
Exploit

Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code …

Verified Metasploit Framework (MSF)

Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)

View Exploit Code →
Exploit

Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters …

Verified

Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection

View Exploit Code →
Application

Siebel Apps - E-Billing by Oracle

cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Gp5000 Firmware by Fujitsu

cpe:2.3:o:fujitsu:gp5000_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Interstage Business Process Manager Analytics by Fujitsu

cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Archiva by Apache

Version Range Affected
From 1.3 (inclusive)
To 1.3.8 (exclusive)
cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Siebel Apps - E-Billing by Oracle

cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.1.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Gp7000F Firmware by Fujitsu

cpe:2.3:o:fujitsu:gp7000f_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Siebel Apps - E-Billing by Oracle

cpe:2.3:a:oracle:siebel_apps_-_e-billing:6.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Struts by Apache

Version Range Affected
From 2.0.0 (inclusive)
To 2.3.15 (inclusive)
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Interstage Business Process Manager Analytics by Fujitsu

cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Primergy Firmware by Fujitsu

cpe:2.3:o:fujitsu:primergy_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Gp-S Firmware by Fujitsu

cpe:2.3:o:fujitsu:gp-s_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Sparc Firmware by Fujitsu

cpe:2.3:o:fujitsu:sparc_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Archiva by Apache

cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Archiva by Apache

cpe:2.3:a:apache:archiva:1.2:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Primepower Firmware by Fujitsu

cpe:2.3:o:fujitsu:primepower_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013…
http://archiva.apache.org/security.html
http://cxsecurity.com/issue/WLB-2014010087
http://osvdb.org/98445
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Executi…
http://seclists.org/fulldisclosure/2013/Oct/96
http://seclists.org/oss-sec/2014/q1/89
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392
http://struts.apache.org/release/2.3.x/docs/s2-016.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2…
http://www.fujitsu.com/global/support/software/security/products-f/interstage-b…
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/bid/61189
http://www.securityfocus.com/bid/64758
http://www.securitytracker.com/id/1029184
http://www.securitytracker.com/id/1032916
http://archiva.apache.org/security.html
http://cxsecurity.com/issue/WLB-2014010087
http://osvdb.org/98445
http://packetstormsecurity.com/files/159629/Apache-Struts-2-Remote-Code-Executi…
http://seclists.org/fulldisclosure/2013/Oct/96
http://seclists.org/oss-sec/2014/q1/89
https://exchange.xforce.ibmcloud.com/vulnerabilities/90392
http://struts.apache.org/release/2.3.x/docs/s2-016.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2…
http://www.fujitsu.com/global/support/software/security/products-f/interstage-b…
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.securityfocus.com/bid/61189
http://www.securityfocus.com/bid/64758
http://www.securitytracker.com/id/1029184
http://www.securitytracker.com/id/1032916