Bugzilla – Bug 975282
VUL-0: CVE-2016-0785: struts: Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence
Last modified: 2016-04-13 11:15:00 UTC
CVE-2016-0785 Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0785 http://www.securitytracker.com/id/1035271 http://struts.apache.org/docs/s2-029.html
not affected