Vulnerabilities > CVE-2005-3745 - Unspecified vulnerability in Apache Struts 1.2.7

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
apache
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Vulnerable Configurations

Part Description Count
Application
Apache
1

Exploit-Db

descriptionApache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability. CVE-2005-3745. Remote exploits for multiple platform
idEDB-ID:26542
last seen2016-02-03
modified2005-11-21
published2005-11-21
reporterIrene Abezgauz
sourcehttps://www.exploit-db.com/download/26542/
titleApache Struts 1.2.7 Error Response Cross-Site Scripting Vulnerability

Redhat

advisories
  • rhsa
    idRHSA-2006:0157
  • rhsa
    idRHSA-2006:0161