RULE(RULE ID:320729)

Rule General Information
Release Date: 2018-04-23
Rule Name: WEB-SERVER Apache Struts XSLTResult File Inclusion Vulnerability -2 (CVE-2016-3082)
Severity:
CVE ID:
Rule Protection Details
Description: XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
Impact: Upgrade to Struts 2.3.20.3, Struts 2.3.24.3 or Struts 2.3.28.1 to solve the problem.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, Other Unix, Linux, Others
Reference: http://struts.apache.org/docs/s2-031.html
SecurityFocusBID:88826
SecurityTrackerID:1035664
Solutions
An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.