CVE-2013-2134 - CVSS 9.3

CVE-2013-2134

Published Date:16 July, 2013CWE-94
Last modified:16 June, 2026
Link:    CVE-2013-2134
NVD:   CVE-2013-2134
UBUNTU:   CVE-2013-2134
REDHAT:   CVE-2013-2134
EUVD: EUVD-2022-3996
CVSS scores for CVE-2013-2134
CVSS v2 : 9.3 HIGH
Access VectorNetwork
Access ComplexityMedium
AuthenticationNone
 
Confidentiality ImpactComplete
Integrity ImpactComplete
Availability ImpactComplete
 
Threat Intelligence
  • Has Public Exploit: Yes
  • CISA KEV Release Date: N/A
  • CISA KEV Due Date: N/A
  • CISA KEV Required Action: N/A
Exploit Prediction in the next 30 days
70%
EPSS
Likely Exploited Vulnerabilities Probability
100%
LEV
Common Weakness Enumeration for CVE-2013-2134

CWE-94 : Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Products affected by CVE-2013-2134
Running on:
struts
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Version Range:
from 2.0.0 (including)up to 2.3.14.3 (excluding)
References