CVE Database
/

CVE-2016-3087

Back to search

CVE-2016-3087

Published: Jun 7, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

VendorProductVersions

n/a

n/a

affected
n/a

References

1036017
vdb-entry
x_refsource_SECTRACK
39919
exploit
x_refsource_EXPLOIT-DB
90960
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now