Apache Struts是美国阿帕奇(Apache)软件基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 使用Struts 1插件的Apache Struts 2.1.x和2.3.x版本存在输入验证错误漏洞。远程攻击者可借助原始消息中的恶意字段值利用该漏洞执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.1.x series | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache struts struts 2 048, CVE-2017-9791. | https://github.com/IanSmith123/s2-048 | POC Details |
| 2 | CVE-2017-9791 | https://github.com/dragoneeg/Struts2-048 | POC Details |
| 3 | Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability | https://github.com/xfer0/CVE-2017-9791 | POC Details |
| 4 | Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9791.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-7670 | Apache Traffic Control 安全漏洞 | |
| CVE-2017-5640 | Apache Impala 安全漏洞 | |
| CVE-2017-5652 | Apache Impala 安全漏洞 |
No comments yet