CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
- Affected products
- Apache Struts, Bamboo, Huawei Vrp, Vmware Vcenter
- Apache Struts
- < 2.3.32, 2.5.10.1
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-755
- NVD status
- Analyzed
- Published
- 2017-03-11
CVE-2017-5638 at NVD
100 known exploits for CVE-2017-5638
Proof-of-concept code and exploit modules indexed by Sploitus
apache-struts-v2-CVE-2017-5638
Struts2-045-Exp
CVE-2017-5638
Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
CVE-2017-5638
web-application-firewall-
CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
struts2-jakarta-inject
struts2-rce
docker-lab-cve-2017-5638-cve-2021-41773
S2-045-EXP-POC-TOOLS
apache-struts2-CVE-2017-5638
ExpStruts
strutsy
st2-046-poc
Apache-Struts-2-CVE-2017-5638-Exploit-
struts2-rce
CVE-2017-5638
StrutsShell
struts-rce-cve-2017-5638
CVE-2017-5638
cve-2017-5638
CVE-2017-5638_struts
CVE-2017-5638
vulnerability_struts-2.3.31
CVE-2017-5638
XworkStruts-RCE
cve-2017-5638
cve-2017-5638
CVE-2017-5638-Apache-Struts2
CVE-2017-5638
struts2_cve-2017-5638
CVE-2017-5638
struts_hack
CVE-2017-5638
Apache-Struts
CVE-2017-5638-Apache-Struts2
CVE-2017-5638
test_struts2_vulnerability_CVE-2017-5638
cve-2017-5638
struts-pwn
CVE-2017-5638
CVE-2017-5638
cve-2017-5638
CVE-2017-5638-Attack-and-Defense
struts-pwn
CVE-2017-5638
CVE-2017-5638
CVE-2018-11776-Python-PoC
Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
CVE-2017-5638
Struts2Vuln
CVE-2017-5638-Mass-Exploit
Detection-struts-cve-2017-5638-detector
CVE-2017-5638
Struts-Apache-ExploitPack
CVE-2017-5638-PoC
Computer-Security-Equifax-2017
Struts2Shell
strutser
cve-2017-5638
struts-rce
Common-Vulnerability-and-Exploit
strutszeiro
CVE-2017-5638
Exploit-CVE-2017-5638
PoC-CVE-2017-5638
CVE-2017-5638
apache-struts-cve-2017-5638-project
CVE-2017-5638-POC
Stutsfi
cybersecurity-struts2
OgnlContentTypeRejectorValve
SC3010-Computer-Security
CVE-2017-5638
CVE-2017-5638-ApacheStruts2.3.5
vulhub-struts2
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
PoC_n_Dockerfile_4_PentestFinalProject_Group02
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for OS Command Injection in Gnu Bash
Exploit for Cross-Site Request Forgery (CSRF) in Concretecms Concrete_Cms
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Out-of-bounds Read in Openssl
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
Apache Struts v3 - Tool To Exploit 3 RCE Vulnerabilities On ApacheStruts
Exploit for CVE-2018-11776
Sn1per v5.0 - Automated Pentest Recon Scanner
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
Exploit for Improper Handling of Exceptional Conditions in Apache Struts
JexBoss - JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool
Exploit for Out-of-bounds Read in Openssl