S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2007-4556 Scanner

CVE-2007-4556 scanner - Code Execution vulnerability in Apache Software Foundation Struts

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2007-4556
6.8
CVSS

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Struts is an open-source web application framework that is used to develop Java EE web applications. The framework is designed to simplify the development of web applications by providing pre-built components for common tasks such as form handling, validation, and database access. Struts is widely used across the industry and is considered one of the most popular web application frameworks.

One of the vulnerabilities that was detected in the Struts software is the CVE-2007-4556 vulnerability. This vulnerability exists in OpenSymphony XWork before versions 1.2.3 and 2.x before 2.0.4, which is used in WebWork and Apache Struts. When the altSyntax is enabled, the software recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression. This allows an attacker to execute arbitrary code or cause a denial of service (infinite loop) by using a form input that begins with a "%{" sequence and ends with a "}" character.

This vulnerability can lead to serious consequences if it is exploited by an attacker. By executing arbitrary code, an attacker can gain unauthorized access to the system and steal sensitive data or perform other malicious activities. A denial of service attack can also cripple the system and render it unusable for an extended period of time, resulting in significant financial and reputation losses for the affected organization.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. With access to advanced security tools and actionable insights, organizations can stay ahead of emerging threats and protect their critical assets from cyber attacks. By partnering with s4e.io, organizations can ensure that their digital assets are secure and protected from cyber attacks.

 

REFERENCES

Solution Advice

To protect against the CVE-2007-4556 vulnerability in the Struts software, certain precautions can be taken. These include:

  • Updating the software to the latest version that fixes the vulnerability.
  • Disabling altSyntax in the Struts configuration.
  • Implementing input validation to ensure that user inputs do not contain malicious code.
  • Using a web application firewall (WAF) to detect and block attacks that exploit this vulnerability.
  • Conducting regular security audits to identify and remediate any vulnerabilities in the software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2007-4556 scanner - Code Execution vulnerability in Apache Software Foundation Struts  | S4E