Red Hat Bugzilla – Bug 788285
CVE-2012-1006 struts2: multiple XSS flaws
Last modified: 2016-03-04 05:44:22 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-1006 to the following vulnerability: Name: CVE-2012-1006 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1006 Assigned: 20120206 Reference: http://secpod.org/advisories/SecPod_Apache_Struts_Multiple_Parsistant_XSS_Vulns.txt Reference: http://secpod.org/blog/?p=450 Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.
Statement: Not Vulnerable. This issue only affects struts 2, it does not affect the versions of struts as shipped with various Red Hat products.