The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag: Apache(2 tweets) Struts(2 tweets)
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
Kai50229182 | https://twitter.com/Kai50229182/status/1647881176638709760/... | Source Kai50229182 1647881176638709760 | 2023/04/17 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
alerts.vulmon.com | 262 |
twitter.com | 4 |
www.us-cert.gov | 4 |
bit.ly | 3 |
User | URL | Info Source |
---|---|---|
Kai50229182 | twitter.com | Show Tweet |
Name | URL |
---|---|
mazen160/struts-pwn | https://github.com/mazen160/struts-pwn |
Iletee/struts2-rce | https://github.com/Iletee/struts2-rce |
immunio/apache-struts2-CVE-2017-5638 | https://github.com/immunio/apache-struts2-CVE-2017-5638 |
jas502n/st2-046-poc | https://github.com/jas502n/st2-046-poc |
xsscx/cve-2017-5638 | https://github.com/xsscx/cve-2017-5638 |
Flyteas/Struts2-045-Exp | https://github.com/Flyteas/Struts2-045-Exp |
jrrdev/cve-2017-5638 | https://github.com/jrrdev/cve-2017-5638 |
jas502n/S2-045-EXP-POC-TOOLS | https://github.com/jas502n/S2-045-EXP-POC-TOOLS |
mthbernardes/strutszeiro | https://github.com/mthbernardes/strutszeiro |
tahmed11/strutsy | https://github.com/tahmed11/strutsy |
Name | URL |
---|---|
mazen160/struts-pwn | github.com |
Iletee/struts2-rce | github.com |
immunio/apache-struts2-CVE-2017-5638 | github.com |
jas502n/st2-046-poc | github.com |
xsscx/cve-2017-5638 | github.com |
Flyteas/Struts2-045-Exp | github.com |
jrrdev/cve-2017-5638 | github.com |
jas502n/S2-045-EXP-POC-TOOLS | github.com |
mthbernardes/strutszeiro | github.com |
tahmed11/strutsy | github.com |