CVE-2012-0394 | Apache Struts up to 2.2.3 DebuggingInterceptor acceptedParamNames code injection (EDB-31434 / Nessus ID 207697)
A vulnerability was found in Apache Struts. It has been classified as critical. This affects an unknown part of the component DebuggingInterceptor. The manipulation of the argument acceptedParamNames leads to code injection.
This vulnerability is uniquely identified as CVE-2012-0394. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to upgrade the affected component.