Apache Struts 2 Multiple Remote Code Execution and File Overwrite Vulnerabilities (safe check) (deprecated)

high Nessus Plugin ID 57691

Synopsis

This plugin has been deprecated.

Description

This plugin has been deprecated due to relying on a timing based check that is prone to false positives. A local plugin will be added that covers this CVE.

See Also

http://struts.apache.org/docs/s2-008.html

Plugin Details

Severity: High

ID: 57691

File Name: struts_xwork_ognl_code_execution_safe1.nasl

Version: 1.15

Type: remote

Family: CGI abuses

Published: 1/25/2012

Updated: 11/20/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2012-0392

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:struts

Exploit Ease: No exploit is required

Patch Publication Date: 1/4/2012

Vulnerability Publication Date: 11/18/2011

Reference Information

CVE: CVE-2012-0392

BID: 51257