Apache Struts Multiple Cross Site Scripting Vulnerabilities (CVE-2007-6726)
Data de publicação: 21 julho 2015
Schweregrad: : Alto
Data do informe: 21 julho 2015
Descrição
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.
Exposição das informações
Apply associated Trend Micro DPI Rules.
Solução
Trend Micro Deep Security DPI Rule Number: 1000552