cve/2016/CVE-2016-3093.md

19 lines
728 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2016-3093](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3093)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20n%2Fa%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ilmari666/cybsec