CVE detail
CVE-2008-6504 — CVE-2008-6504
Published 2009-03-23 · Modified 2026-06-16 · Vendor opensymphony · Product xwork · Source nvd
UNKNOWN
severity
CVSS-derived band
0.3635
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References