ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.

Published: 2016-07-04

CVSS: 8.2

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Download CVE-2016-1182 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://connollyfinan.ie/poc-644-cve-2017-5618/

https://connollyfinan.ie/poc-597-cve-2017-1000253/

https://connollyfinan.ie/poc-169-cve-2017-8046/

https://connollyfinan.ie/poc-544-cve-2021-40438/

https://connollyfinan.ie/poc-62-cve-2025-6558/