Sploitus

CVE-2017-9805

47 known exploits for CVE-2017-9805

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Affected products
Apache Struts, Xstream
Apache Struts
< 2.3.34, 2.5.13
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
99.4% (100th percentile)
Weakness
CWE-502
NVD status
Analyzed
Published
2017-09-15
CVE-2017-9805 at NVD
Authoritative description, scoring and affected products

47 known exploits for CVE-2017-9805

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2017-9805
2026-08-27 KitPloitKITPLOIT
CVE-2017-9805-Exploit
2026-08-27 KitPloitKITPLOIT
struts2-rce-cve-2017-9805-ruby
2026-08-27 KitPloitKITPLOIT
CVE-2017-9805
2026-08-27 KitPloitKITPLOIT
cve-2017-9805.py
2026-08-27 KitPloitKITPLOIT
apache-struts-cve-2017-9805
2026-08-27 KitPloitKITPLOIT
struts-rce-cve-2017-9805
2026-08-26 KitPloitKITPLOIT
-CVE-2017-9805
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805-Exploit
2026-08-26 KitPloitKITPLOIT
struts_rest_rce_fuzz-CVE-2017-9805-
2026-08-26 KitPloitKITPLOIT
-CVE-2017-9805-
2026-08-26 KitPloitKITPLOIT
struts-s2-052-deserialization-rce-lab
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805-Exploit
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805
2026-08-26 KitPloitKITPLOIT
struts-pwn_CVE-2017-9805
2026-08-26 KitPloitKITPLOIT
S2-052
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805-Apache-Struts-Fuzz-N-Sploit
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805---Documentation---IT19143378
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805-S2-052
2026-08-26 KitPloitKITPLOIT
apache-struts-pwn_CVE-2017-9805
2026-08-26 KitPloitKITPLOIT
CVE-2017-9805_example_build
2026-08-25 KitPloitKITPLOIT
CVE-Apache-Ecosystem
2026-08-13 chengbochuan3GITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2026-03-16 Experience-rookieGITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2026-02-28 7s26simonGITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2026-01-04 Fl5xiaGITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2022-10-03 Shakun8GITHUB
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
2019-05-12 KitPloitKITPLOIT
Sn1per v6.0 - Automated Pentest Framework For Offensive Security Experts
2018-11-24 KitPloitKITPLOIT
Sn1per v5.0 - Automated Pentest Recon Scanner
2018-07-05 KitPloitKITPLOIT
Apache Struts REST Plugin XStream RCE
2018-04-20 Dsquare SecurityD2
Exploit for Deserialization of Untrusted Data in Apache Struts
2017-12-04 chrisjd20GITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2017-09-10 Lone-RangerGITHUB
Exploit for Deserialization of Untrusted Data in Apache Struts
2017-09-09 mazen160GITHUB
Apache Struts REST plugin XStream deserialization vulnerability
2017-09-08 SAINT CorporationSAINT
Apache Struts REST plugin XStream deserialization vulnerability
2017-09-08 SAINT CorporationSAINT
Apache Struts REST plugin XStream deserialization vulnerability
2017-09-08 SAINT CorporationSAINT
Apache Struts 2.5 - Remote Code Execution Exploit
2017-09-07 WarflopZDTPython
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution Exploit
2017-09-07 metasploitZDTRuby
Apache Struts 2.5.12 XStream Remote Code Execution
2017-09-07 WarflopPACKETSTORMPython
Apache Struts 2 REST Plugin XStream Remote Code Execution
2017-09-07 wvuPACKETSTORMRuby
Exploit for Deserialization of Untrusted Data in Apache Struts
2017-09-07 hahwulGITHUB
Apache Struts 2.5 2.5.12 - REST Plugin XStream Remote Code Execution
2017-09-06 WarflopEXPLOITPACKPython
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
2017-09-06 WarflopEXPLOITDBPython
Apache Struts2 S2-052 (CVE-2017-9805)
2017-09-06 RootSEEBUG
Exploit for Deserialization of Untrusted Data in Apache Struts
2017-09-06 luc10GITHUB
Apache Struts 2 REST Plugin XStream RCE
2017-09-05 Man Yue Mo, wvu <wvu@metasploit.com>METASPLOITRuby
Exploit for OS Command Injection in Gnu Bash
2017-01-02 PortSwiggerGITHUB