S4E just found a high-severity finding from cve-2019-11248 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2013-1965 Scanner

CVE-2013-1965 scanner - OGNL Injection (Object-Graph Navigation Language) vulnerability in Apache Struts Showcase App

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.3
CVSS
Description

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

Apache Struts Showcase App is an open-source web application framework that was developed to streamline the process of building enterprise-ready Java web applications. Struts has become a popular choice for developers because it offers a combination of simplicity, power, and flexibility. The framework makes it easy for developers to create web applications that can handle complex business logic.

CVE-2013-1965 is a vulnerability that was identified in Struts 2 before 2.3.14.3. The vulnerability allows remote attackers to execute arbitrary OGNL code via a crafted parameter name. The issue arises because the application does not properly handle the parameter when invoking a redirect. OGNL is an expression language that is used in Struts to manipulate objects, and this vulnerability makes it possible for attackers to access sensitive data or execute malicious code on the server.

When exploited, the CVE-2013-1965 vulnerability can lead to significant damage to an organization. Attackers can use this vulnerability to gain access to sensitive data, including usernames, passwords, and financial information. They can also use the vulnerability to execute arbitrary code on the server, allowing them to take control of the system or deploy malware.

Thanks to the pro features of the s4e.io platform, those who read this article can quickly and easily learn about vulnerabilities in their digital assets. The platform helps organizations identify vulnerabilities in their digital assets and provides actionable recommendations for remediation. Users can also monitor their assets for ongoing threats and attacks, ensuring that their systems are always secure.

 

REFERENCES

Solution Advice

To protect against the CVE-2013-1965 vulnerability, it is essential to take the following precautions:

  • Upgrade to a version of Struts that is not affected by the vulnerability or apply the necessary patches.
  • Implement robust input validation to prevent attackers from injecting malicious code through user input.
  • Regularly monitor system logs and network traffic to detect unusual activity that may indicate a security breach.
  • Educate employees about the importance of cybersecurity and the risks associated with opening suspicious emails or clicking on links from unknown sources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2013-1965 scanner - OGNL Injection (Object-Graph Navigation Language) vulnerability in Apache Struts Showcase App | S4E