vendor:
Struts2
by:
Anonymous
9,8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Struts2
Affected Version From: 2.3.15.1
Affected Version To: 2.3.31
Patch Exists: YES
Related CWE: CVE-2017-9791
CPE: a:apache:struts:2.3.15.1
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Exploit Apache Struts2 S2-048
This exploit is for Apache Struts2 S2-048 vulnerability. It uses a payload to exploit the vulnerability and execute a command on the server. The payload is used to clear the excluded package and class names from the OgnlUtil class and set the member access to the default. This allows the attacker to execute the command on the server.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of Apache Struts2. It is also recommended to use the latest version of Java and to disable the OGNL language.