CVE-2008-6682
Summary
| CVE | CVE-2008-6682 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-09 15:08:35 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Struts Multiple Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Nabble - Struts - User - Feedback: WW-2414, XSS attack is possible if using <s:url ...> and <s:a ...> | af854a3a-2127-422b-91ae-364da2661108 | www.nabble.com | Patch |
| [#WW-2414] Tags <s:url> and <s:a> do not encode URLs - Apache Struts JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Vendor Advisory |
| Nabble - Struts - User - Feedback: WW-2414, XSS attack is possible if using <s:url ...> and <s:a ...> | af854a3a-2127-422b-91ae-364da2661108 | www.nabble.com | Patch |
| [#WW-2427] s:a does not HTML-escape "href" attribute value - Apache Struts JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997339 Java (Maven) Security Update for org.apache.struts:struts2-core (GHSA-jgcr-9c2q-rvp8)