CVE-2016-3081: Apache Struts
CISA (English)
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
- 廠商
- Apache
- 產品
- Struts
- 漏洞
- Apache Struts Command Injection Vulnerability
- 加入日期
- 2026年10月8日
- CISA 修補期限(美國聯邦機關)
- 2026年10月11日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-77
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.08
關於本頁
Apache Struts包含一個命令注入弱點,可以允許遠端攻擊者透過方法執行任意程式碼:啟用動態方法呼叫時的字首。