{"blog_url":"https://boscono.hatenablog.com/","provider_name":"Hatena Blog","image_url":null,"author_name":"boscono","width":"100%","type":"rich","provider_url":"https://hatena.blog","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fboscono.hatenablog.com%2Fentry%2F2014%2F04%2F26%2F155404\" title=\"CVE2014-0094\u306eStruts1\u306e\u30d1\u30c3\u30c1 - \u3066\u304d\u3068\u3046\u306a\u30e1\u30e2\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","categories":["Security"],"author_url":"https://blog.hatena.ne.jp/boscono/","version":"1.0","title":"CVE2014-0094\u306eStruts1\u306e\u30d1\u30c3\u30c1","url":"https://boscono.hatenablog.com/entry/2014/04/26/155404","published":"2014-04-26 15:54:04","blog_title":"\u3066\u304d\u3068\u3046\u306a\u30e1\u30e2","description":"\u30d1\u30c3\u30c1\u3068\u3044\u3046\u304borg.apache.struts.util.RequestUtils#populate\u3092\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u4fee\u6b63\u3059\u308c\u3070\u826f\u3055\u3052\u3002\u30c6\u30b9\u30c8\u3061\u3083\u3093\u3068\u3084\u3063\u3066\u3044\u306a\u3044\u306e\u3067\u3001\u81ea\u5df1\u8cac\u4efb\u3067\u3002 public static void populate(Object bean, String prefix, String suffix, HttpServletRequest request) throws ServletException { ... while (names.hasMoreElements()) { // Populate parameters, except \"standard\" strut\u2026","height":"190"}