Java-monitor RSS bot
10-01-2012, 02:22
** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0394)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0394)