Sploitus

CVE-2013-2251

19 known exploits for CVE-2013-2251

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

Affected products
Apache Struts
Apache Archiva
< 1.3.8, 1.2, 1.2.2
Apache Struts
≤ 2.3.15
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
100.0% (100th percentile)
Weakness
CWE-74
NVD status
Analyzed
Published
2013-07-18
CVE-2013-2251 at NVD
Authoritative description, scoring and affected products

19 known exploits for CVE-2013-2251

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2013-2251
2026-08-27 KitPloitKITPLOIT
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
2020-10-20 Jonatas FilEXPLOITDBPython
Apache Struts 2 Remote Code Execution
2020-10-20 Jonatas FilPACKETSTORMPython
Apache Struts v3 - Tool To Exploit 3 RCE Vulnerabilities On ApacheStruts
2018-08-26 KitPloitKITPLOIT
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
2014-01-14 Takeshi TeradaEXPLOITDB
Apache Struts2 2.0.0 2.3.15 - Prefixed Parameters OGNL Injection
2014-01-14 Takeshi TeradaEXPLOITPACK
Apache-Struts DefaultActionMapper < 2.3.15.1 RCE Linux
2013-10-20 Dsquare SecurityD2
Struts2 2.3.15 OGNL Injection
2013-08-13 Takeshi TeradaPACKETSTORM
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
2013-08-01 SAINT CorporationSAINT
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
2013-08-01 SAINT CorporationSAINT
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
2013-08-01 SAINT CorporationSAINT
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
2013-08-01 SAINT CorporationSAINT
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
2013-07-27 MetasploitEXPLOITDBRuby
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
2013-07-26 metasploitZDTRuby
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
2013-07-25 sinn3rPACKETSTORMRuby
DSquare Exploit Pack: D2SEC_STRUTS4
2013-07-20 DSquareD2
Immunity Canvas: STRUTS2_DEFAULT_ACTION_MAPPER
2013-07-20 Immunity CanvasCANVAS
Apache Struts2 多个前缀参数远程命令执行漏洞(CVE-2013-2251)
2013-07-17 RootSEEBUG
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
2013-07-02 Takeshi Terada, sinn3r <sinn3r@metasploit.com>, juan vazquez <juan.vazquez@metasploit.com>METASPLOITRuby