Sploitus

CVE-2017-5638

100 known exploits for CVE-2017-5638

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

Apache Struts
< 2.3.32, 2.5.10.1
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
100.0% (100th percentile)
Weakness
CWE-755
NVD status
Analyzed
Published
2017-03-11
CVE-2017-5638 at NVD
Authoritative description, scoring and affected products

100 known exploits for CVE-2017-5638

Proof-of-concept code and exploit modules indexed by Sploitus

apache-struts-v2-CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
Struts2-045-Exp
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
web-application-firewall-
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
2026-08-27 KitPloitKITPLOIT
struts2-jakarta-inject
2026-08-27 KitPloitKITPLOIT
struts2-rce
2026-08-27 KitPloitKITPLOIT
docker-lab-cve-2017-5638-cve-2021-41773
2026-08-27 KitPloitKITPLOIT
S2-045-EXP-POC-TOOLS
2026-08-27 KitPloitKITPLOIT
apache-struts2-CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
ExpStruts
2026-08-27 KitPloitKITPLOIT
strutsy
2026-08-27 KitPloitKITPLOIT
st2-046-poc
2026-08-27 KitPloitKITPLOIT
Apache-Struts-2-CVE-2017-5638-Exploit-
2026-08-27 KitPloitKITPLOIT
struts2-rce
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
StrutsShell
2026-08-27 KitPloitKITPLOIT
struts-rce-cve-2017-5638
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
cve-2017-5638
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638_struts
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
vulnerability_struts-2.3.31
2026-08-27 KitPloitKITPLOIT
CVE-2017-5638
2026-08-27 KitPloitKITPLOIT
XworkStruts-RCE
2026-08-26 KitPloitKITPLOIT
cve-2017-5638
2026-08-26 KitPloitKITPLOIT
cve-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638-Apache-Struts2
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
struts2_cve-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
struts_hack
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
Apache-Struts
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638-Apache-Struts2
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
test_struts2_vulnerability_CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
cve-2017-5638
2026-08-26 KitPloitKITPLOIT
struts-pwn
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
cve-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638-Attack-and-Defense
2026-08-26 KitPloitKITPLOIT
struts-pwn
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2017-5638
2026-08-26 KitPloitKITPLOIT
CVE-2018-11776-Python-PoC
2026-08-26 KitPloitKITPLOIT
Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
Struts2Vuln
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638-Mass-Exploit
2026-08-25 KitPloitKITPLOIT
Detection-struts-cve-2017-5638-detector
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
Struts-Apache-ExploitPack
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638-PoC
2026-08-25 KitPloitKITPLOIT
Computer-Security-Equifax-2017
2026-08-25 KitPloitKITPLOIT
Struts2Shell
2026-08-25 KitPloitKITPLOIT
strutser
2026-08-25 KitPloitKITPLOIT
cve-2017-5638
2026-08-25 KitPloitKITPLOIT
struts-rce
2026-08-25 KitPloitKITPLOIT
Common-Vulnerability-and-Exploit
2026-08-25 KitPloitKITPLOIT
strutszeiro
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
Exploit-CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
PoC-CVE-2017-5638
2026-08-25 KitPloitKITPLOIT
CVE-2017-5638
2026-08-24 KitPloitKITPLOIT
apache-struts-cve-2017-5638-project
2026-08-24 KitPloitKITPLOIT
CVE-2017-5638-POC
2026-08-24 KitPloitKITPLOIT
Stutsfi
2026-08-24 KitPloitKITPLOIT
cybersecurity-struts2
2026-08-24 KitPloitKITPLOIT
OgnlContentTypeRejectorValve
2026-08-24 KitPloitKITPLOIT
SC3010-Computer-Security
2026-08-24 KitPloitKITPLOIT
CVE-2017-5638
2026-08-22 KitPloitKITPLOIT
CVE-2017-5638-ApacheStruts2.3.5
2026-08-22 KitPloitKITPLOIT
vulhub-struts2
2026-08-21 KitPloitKITPLOIT
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2026-05-26 DungsocoolGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2026-05-18 MajaktechGITHUB
PoC_n_Dockerfile_4_PentestFinalProject_Group02
2026-04-14 BaodeptraiiGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2026-04-11 Kouf320GITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2026-02-20 soufiane-benchahydGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2026-01-04 louislafosseGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2025-10-29 Terry-tenGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2025-08-25 iampetruGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2025-08-09 mirrors_knownsecGITEE
Exploit for OS Command Injection in Gnu Bash
2025-07-27 mirrors_albinowaxGITEE
Exploit for Cross-Site Request Forgery (CSRF) in Concretecms Concrete_Cms
2024-09-04 kloutkakeGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2020-11-27 nanshen522GITEE
Exploit for Out-of-bounds Read in Openssl
2019-08-19 aaaddcGITEE
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
2019-05-12 KitPloitKITPLOIT
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
2018-11-24 KitPloitKITPLOIT
Apache Struts v3 - Tool To Exploit 3 RCE Vulnerabilities On ApacheStruts
2018-08-26 KitPloitKITPLOIT
Exploit for CVE-2018-11776
2018-08-24 hook-s3cGITHUB
Sn1per v5.0 - Automated Pentest Recon Scanner
2018-07-05 KitPloitKITPLOIT
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2018-06-26 IleteeGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2018-05-13 win3zzGITHUB
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
2018-02-15 0x00-0x00GITHUB
JexBoss - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool
2017-12-18 KitPloitKITPLOIT
Exploit for Out-of-bounds Read in Openssl
2017-07-31 fastapiGITEE