Skip to content
Noroxi

opensymphony records

4 published records for vendor opensymphony.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • CVE-2007-4556
    35Monitor

    Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all inp

    MediumCVSS 6.8Proof of conceptEPSS 26%

    opensymphony · xworkAug 27, 2007

  • CVE-2008-6504
    31Monitor

    ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not

    MediumCVSS 5.0Proof of conceptEPSS 37%

    opensymphony · xworkMar 23, 2009

  • CVE-2011-2088
    22Monitor

    XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive

    MediumCVSS 5.0No exploitEPSS 6%

    apache · strutsMay 13, 2011

  • CVE-2011-1772
    20Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWo

    LowCVSS 2.6Proof of conceptEPSS 33%

    apache · strutsMay 13, 2011