← Back

CVE-2009-1275

nvd nist
Published: Apr 9, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.

Affected (2)

Products: Apache: Tiles
1 product
Tiles
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Apache
Version 2.1.0
Version 2.1.1
Running on/withPlatform Versions
Apache
Struts
All versions

References (6)

Timeline

No history available yet.