CVE-2012-0393 | Apache Struts up to 2.3.1 ParameterInterceptor access control (EDB-18329 / Nessus ID 69101)
A vulnerability has been found in Apache Struts and classified as critical. Affected by this vulnerability is an unknown functionality of the component ParameterInterceptor. The manipulation with the input ../../ leads to improper access controls.
This vulnerability is known as CVE-2012-0393. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.