Sploitus

CVE-2018-11776

62 known exploits for CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Affected products
Apache Struts
Apache Struts
< 2.3.35, 2.5.17
Fix
Available
CVSS 2.0
9.3 HIGH
CVSS 3.1
8.1 HIGH
EPSS
100.0% (100th percentile)
NVD status
Analyzed
Published
2018-08-22
CVE-2018-11776 at NVD
Authoritative description, scoring and affected products

62 known exploits for CVE-2018-11776

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2018-11776
2026-08-27 KitPloitKITPLOIT
CVE-2018-11776
2026-08-27 KitPloitKITPLOIT
struts-pwn_CVE-2018-11776
2026-08-27 KitPloitKITPLOIT
S2-057-CVE-2018-11776
2026-08-27 KitPloitKITPLOIT
St2-057
2026-08-27 KitPloitKITPLOIT
Apache-Struts-0Day-Exploit
2026-08-27 KitPloitKITPLOIT
CVE-2018-11776
2026-08-27 KitPloitKITPLOIT
Strutter
2026-08-27 KitPloitKITPLOIT
cve-2018-11776-docker
2026-08-26 KitPloitKITPLOIT
CVE-2018-11776
2026-08-26 KitPloitKITPLOIT
CVE-2018-11776-Python-PoC
2026-08-26 KitPloitKITPLOIT
ApacheStruts-CVE-2018-11776
2026-08-26 KitPloitKITPLOIT
CVE-2018-11776
2026-08-26 KitPloitKITPLOIT
cve-2018-11776
2026-08-26 KitPloitKITPLOIT
CVE-2018-11776-FIS
2026-08-25 KitPloitKITPLOIT
CVE-2018-11776
2026-08-24 KitPloitKITPLOIT
Apache-Struts-Shodan-Exploit
2026-08-24 KitPloitKITPLOIT
apche-struts-vuln-demo-cve-2018-11776
2026-08-22 KitPloitKITPLOIT
mitaka v2.10.0
2026-08-02 KitPloitKITPLOIT
Exploit for OS Command Injection in Gnu Bash
2025-07-27 mirrors_albinowaxGITEE
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 thomsdevGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 byteofandriGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 orangmudaGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 byteofjoshuaGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 rakhanobeGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 onsecuredevGITHUB
Exploit for Expression Language Injection in Atlassian Confluence_Data_Center
2021-10-06 oxctdevGITHUB
Exploit for CVE-2018-11776
2020-06-18 cjwGITEE
Exploit for CVE-2018-11776
2020-01-02 sssGITEE
Exploit for CVE-2018-11776
2019-11-12 githubGITHUB
Exploit for CVE-2018-11776
2019-10-10 ArunBhandariiGITHUB
Exploit for CVE-2018-11776
2019-10-10 LightC0derGITHUB
Exploit for CVE-2018-11776
2019-10-10 showerlemonGITHUB
Sn1per v7.0 - Automated Pentest Framework For Offensive Security Experts
2019-05-12 KitPloitKITPLOIT
Apache Struts 2 Multiple Tags Result Namespace Handling RCE
2018-10-20 Dsquare SecurityD2
Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit)
2018-09-10 MetasploitEXPLOITDBRuby
Apache Struts 2 Namespace Redirect OGNL Injection Exploit
2018-09-08 zdtZDTRuby
Apache Struts 2 Namespace Redirect OGNL Injection
2018-09-07 wvuPACKETSTORMRuby
Exploit for CVE-2018-11776
2018-08-29 649GITHUB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2) Exploit
2018-08-28 hook-s3cZDTPython
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1) Exploit
2018-08-28 Mazin AhmedZDTPython
Exploit for CVE-2018-11776
2018-08-28 brianwrfGITHUB
Exploit for CVE-2018-11776
2018-08-28 tuxotronGITHUB
Exploit for CVE-2018-11776
2018-08-27 EkultekGITHUB
Apache Struts v3 - Tool To Exploit 3 RCE Vulnerabilities On ApacheStruts
2018-08-26 KitPloitKITPLOIT
Apache Struts 2.3 2.3.34 2.5 2.5.16 - Remote Code Execution (1)
2018-08-26 Mazin AhmedEXPLOITPACKPython
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
2018-08-26 Mazin AhmedEXPLOITDBPython
Apache Struts 2.3 / 2.5 Remote Code Execution
2018-08-26 Mazin AhmedPACKETSTORMPython
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
2018-08-25 hook-s3cEXPLOITDBPython
Apache Struts 2.3 / 2.5 Remote Code Execution
2018-08-25 hook-s3cPACKETSTORMPython
Exploit for CVE-2018-11776
2018-08-25 bhdreshGITHUB
Exploit for CVE-2018-11776
2018-08-25 mazen160GITHUB
Exploit for CVE-2018-11776
2018-08-25 knqyf263GITHUB
Apache Struts 2.x Remote Code Execution Vulnerability
2018-08-24 Man Yue MoZDT
Exploit for CVE-2018-11776
2018-08-24 hook-s3cGITHUB
Exploit for CVE-2018-11776
2018-08-24 jiguangfutureGITHUB
Exploit for CVE-2018-11776
2018-08-24 jiguangrstGITHUB
Exploit for CVE-2018-11776
2018-08-24 jiguangsdfGITHUB
Exploit for CVE-2018-11776
2018-08-24 jiguanginGITHUB
Exploit for CVE-2018-11776
2018-08-23 xfox64xGITHUB
Apache Struts 2 Namespace Redirect OGNL Injection
2018-08-22 Man Yue Mo, hook-s3c, asoto-r7, wvu <wvu@metasploit.com>METASPLOITRuby
Exploit for OS Command Injection in Gnu Bash
2017-01-02 PortSwiggerGITHUB