CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
- Affected products
- Apache Struts
- Apache Struts
- = 2.3.1, 2.3.1.1, 2.3.1.2, 2.3.3, 2.3.4, 2.3.4.1, 2.3.7, 2.3.8, 2.3.12, 2.3.14, 2.3.14.1, 2.3.14.2, 2.3.14.3, 2.3.15, 2.3.15.1, 2.3.15.2, 2.3.15.3, 2.3.16, 2.3.16.1, 2.3.16.2, 2.3.16.3, 2.3.20, 2.3.20.1, 2.3.20.3, 2.3.24, 2.3.24.1, 2.3.24.3, 2.3.28, 2.3.28.1, 2.3.29, 2.3.30, 2.3.31, 2.3.32
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 98.8% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2017-07-10
CVE-2017-9791 at NVD
20 known exploits for CVE-2017-9791
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Input Validation in Joomla Joomla\!
Vulmap - Web Vulnerability Scanning And Verification Tools
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Exploit for Improper Input Validation in Joomla Joomla\!
Apache Struts 2 Struts 1 plugin Showcase OGNL code execution
Apache Struts 2 Struts 1 plugin Showcase OGNL code execution
Apache Struts 2 Struts 1 plugin Showcase OGNL code execution
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution Exploit
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
Apache Struts 2 Struts 1 Plugin Showcase OGNL Code Execution
Exploit for Improper Input Validation in Joomla Joomla\!
Apache Struts 2 Struts 1 Plugin ActionMessage < 2.3.32 RCE
Apache Struts 2 Struts 1 Plugin Showcase OGNL Code Execution
Apache Struts 2.3.x Showcase - Remote Code Execution (PoC) Exploit
Apache Struts 2.3.x Showcase Remote Code Execution
Apache Struts 2.3.x Showcase - Remote Code Execution
Apache Struts 2.3.x Showcase - Remote Code Execution