vendor:
Struts2
by:
Man Yue Mo
N/A
CVSS
N/A
Remote Code Execution
94
CWE
Product Name: Struts2
Affected Version From: Apache Struts 2.3.5 - Struts 2.3.31
Affected Version To: Apache Struts 2.3.5 - Struts 2.3.31
Patch Exists: YES
Related CWE: CVE-2017-5638
CPE: o:apache:struts:2.3.5
Other Scripts:
N/A
Tags: cve,cve2017,apache,kev,msf,struts,rce
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'shodan-query': 'html:"Apache Struts"', 'verified': True, 'vendor': 'apache', 'product': 'struts'}
Platforms Tested: Windows, Linux, Mac
2017
Apache Struts2 Remote Code Execution Vulnerability
Apache Struts 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 is susceptible to remote command injection attacks. The Jakarta Multipart parser has incorrect exception handling and error-message generation during file upload attempts, which can allow an attacker to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header. This was exploited in March 2017 with a Content-Type header containing a #cmd= string.
Mitigation:
Upgrade to Apache Struts 2.3.32 or later.