CVE-2013-2248

CVSS v2.0 5.8 (Medium)
58% Progress
EPSS 96.89 % (100th)
96.89% Progress
Affected Products 1
Advisories 1

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-07-20 03:37:30
(11 years ago)
Updated Date
2016-12-31 02:59:02
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Struts 2.0.0 cpe:2.3:a:apache:struts:2.0.0
  Apache Struts 2.0.1 cpe:2.3:a:apache:struts:2.0.1
  Apache Struts 2.0.2 cpe:2.3:a:apache:struts:2.0.2
  Apache Struts 2.0.3 cpe:2.3:a:apache:struts:2.0.3
  Apache Struts 2.0.4 cpe:2.3:a:apache:struts:2.0.4
  Apache Struts 2.0.5 cpe:2.3:a:apache:struts:2.0.5
  Apache Struts 2.0.6 cpe:2.3:a:apache:struts:2.0.6
  Apache Struts 2.0.7 cpe:2.3:a:apache:struts:2.0.7
  Apache Struts 2.0.8 cpe:2.3:a:apache:struts:2.0.8
  Apache Struts 2.0.9 cpe:2.3:a:apache:struts:2.0.9
  Apache Struts 2.0.10 cpe:2.3:a:apache:struts:2.0.10
  Apache Struts 2.0.11 cpe:2.3:a:apache:struts:2.0.11
  Apache Struts 2.0.11.1 cpe:2.3:a:apache:struts:2.0.11.1
  Apache Struts 2.0.11.2 cpe:2.3:a:apache:struts:2.0.11.2
  Apache Struts 2.0.12 cpe:2.3:a:apache:struts:2.0.12
  Apache Struts 2.0.13 cpe:2.3:a:apache:struts:2.0.13
  Apache Struts 2.0.14 cpe:2.3:a:apache:struts:2.0.14
  Apache Struts 2.1.0 cpe:2.3:a:apache:struts:2.1.0
  Apache Struts 2.1.1 cpe:2.3:a:apache:struts:2.1.1
  Apache Struts 2.1.2 cpe:2.3:a:apache:struts:2.1.2
  Apache Struts 2.1.3 cpe:2.3:a:apache:struts:2.1.3
  Apache Struts 2.1.4 cpe:2.3:a:apache:struts:2.1.4
  Apache Struts 2.1.5 cpe:2.3:a:apache:struts:2.1.5
  Apache Struts 2.1.6 cpe:2.3:a:apache:struts:2.1.6
  Apache Struts 2.1.8 cpe:2.3:a:apache:struts:2.1.8
  Apache Struts 2.1.8.1 cpe:2.3:a:apache:struts:2.1.8.1
  Apache Struts 2.2.1 cpe:2.3:a:apache:struts:2.2.1
  Apache Struts 2.2.1.1 cpe:2.3:a:apache:struts:2.2.1.1
  Apache Struts 2.2.3 cpe:2.3:a:apache:struts:2.2.3
  Apache Struts 2.2.3.1 cpe:2.3:a:apache:struts:2.2.3.1
  Apache Struts 2.3.1 cpe:2.3:a:apache:struts:2.3.1
  Apache Struts 2.3.1.1 cpe:2.3:a:apache:struts:2.3.1.1
  Apache Struts 2.3.1.2 cpe:2.3:a:apache:struts:2.3.1.2
  Apache Struts 2.3.3 cpe:2.3:a:apache:struts:2.3.3
  Apache Struts 2.3.4 cpe:2.3:a:apache:struts:2.3.4
  Apache Struts 2.3.4.1 cpe:2.3:a:apache:struts:2.3.4.1
  Apache Struts 2.3.7 cpe:2.3:a:apache:struts:2.3.7
  Apache Struts 2.3.8 cpe:2.3:a:apache:struts:2.3.8
  Apache Struts 2.3.12 cpe:2.3:a:apache:struts:2.3.12
  Apache Struts 2.3.14 cpe:2.3:a:apache:struts:2.3.14
  Apache Struts 2.3.14.1 cpe:2.3:a:apache:struts:2.3.14.1
  Apache Struts 2.3.14.2 cpe:2.3:a:apache:struts:2.3.14.2
  Apache Struts 2.3.14.3 cpe:2.3:a:apache:struts:2.3.14.3
  Apache Struts 2.3.15 cpe:2.3:a:apache:struts:2.3.15
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...