A vulnerability was found in Apache Struts 1.3.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file struts-examples/upload/upload-submit.do. The manipulation of the argument name leads to cross site scripting.
This vulnerability is handled as CVE-2012-1007. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
Many organizations struggle with password policies that look strong on paper but fail in practice because they're too rigid to follow, too vague to enforce, or disconnected from real security needs. Some are so tedious and complex that employees post passwords on sticky notes under keyboards, monitors, or desk drawers. Others set rules so loose they may as well not exist. And many simply copy