The Jakarta Multipart Parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts allowing an attacker to execute code remotely.
For more information, feel free to check our complete tutorial
[ad_2]
source