01642 06 11 11 Arrange Call

Remote Code Execution via ClassLoader Manipulation in Apache Struts

CVE-2014-0094 · MEDIUM

CVE-2014-0094

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Learn more about our Cis Benchmark Audit For Apache Http Server.