{"id":"CVE-2013-2135","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-2135","summary":"Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both \"${}\" and \"%{}\" sequences, which causes…","details":"Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both \"${}\" and \"%{}\" sequences, which causes the OGNL code to be evaluated twice.","published":"2013-07-16T18:55:01.403","modified":"2026-06-16T23:52:48.707","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"http://struts.apache.org/development/2.x/docs/s2-015.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/64758"},{"type":"ADVISORY","url":"https://cwiki.apache.org/confluence/display/WW/S2-015"},{"type":"ADVISORY","url":"http://struts.apache.org/development/2.x/docs/s2-015.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/64758"},{"type":"ADVISORY","url":"https://cwiki.apache.org/confluence/display/WW/S2-015"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:52:48.707"}}