.. / CVE-2017-9791

Exploit for Apache Struts2 S2-053 - Remote Code Execution (CVE-2017-9791)

Description:

Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

Nuclei Template

View the template here CVE-2017-9791.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-9791.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2017-9791
http://www.securitytracker.com/id/1038838
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html
http://web.archive.org/web/20211207175819/https://securitytracker.com/id/1038838
http://struts.apache.org/docs/s2-048.html
https://security.netapp.com/advisory/ntap-20180706-0002/