CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
- Affected products
- Apache Struts, Xstream
- Apache Struts
- < 2.3.34, 2.5.13
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 99.4% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2017-09-15
CVE-2017-9805 at NVD
47 known exploits for CVE-2017-9805
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2017-9805
CVE-2017-9805-Exploit
struts2-rce-cve-2017-9805-ruby
CVE-2017-9805
cve-2017-9805.py
apache-struts-cve-2017-9805
struts-rce-cve-2017-9805
-CVE-2017-9805
CVE-2017-9805-Exploit
struts_rest_rce_fuzz-CVE-2017-9805-
-CVE-2017-9805-
struts-s2-052-deserialization-rce-lab
CVE-2017-9805-Exploit
CVE-2017-9805
struts-pwn_CVE-2017-9805
S2-052
CVE-2017-9805-Apache-Struts-Fuzz-N-Sploit
CVE-2017-9805---Documentation---IT19143378
CVE-2017-9805-S2-052
apache-struts-pwn_CVE-2017-9805
CVE-2017-9805_example_build
CVE-Apache-Ecosystem
Exploit for Deserialization of Untrusted Data in Apache Struts
Exploit for Deserialization of Untrusted Data in Apache Struts
Exploit for Deserialization of Untrusted Data in Apache Struts
Exploit for Deserialization of Untrusted Data in Apache Struts
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
Sn1per v5.0 - Automated Pentest Recon Scanner
Apache Struts REST Plugin XStream RCE
Exploit for Deserialization of Untrusted Data in Apache Struts
Exploit for Deserialization of Untrusted Data in Apache Struts
Exploit for Deserialization of Untrusted Data in Apache Struts
Apache Struts REST plugin XStream deserialization vulnerability
Apache Struts REST plugin XStream deserialization vulnerability
Apache Struts REST plugin XStream deserialization vulnerability
Apache Struts 2.5 - Remote Code Execution Exploit
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution Exploit
Apache Struts 2.5.12 XStream Remote Code Execution
Apache Struts 2 REST Plugin XStream Remote Code Execution
Exploit for Deserialization of Untrusted Data in Apache Struts
Apache Struts 2.5 2.5.12 - REST Plugin XStream Remote Code Execution
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
Apache Struts2 S2-052 (CVE-2017-9805)
Exploit for Deserialization of Untrusted Data in Apache Struts
Apache Struts 2 REST Plugin XStream RCE
Exploit for OS Command Injection in Gnu Bash