Exploited Vulnerabilities Daily
🌐 繁體中文

CVE-2016-3081: Apache Struts

CISA (English)

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

廠商
Apache
產品
Struts
漏洞
Apache Struts Command Injection Vulnerability
加入日期
2026年10月8日
CISA 修補期限(美國聯邦機關)
2026年10月11日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-77

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.08

關於本頁

Apache Struts包含一個命令注入弱點,可以允許遠端攻擊者透過方法執行任意程式碼:啟用動態方法呼叫時的字首。