Sploitus

Exploit for Expression Language Injection in Apache Struts

githubexploit · 2022-04-15

Exploit Code

README21 lines
## https://sploitus.com/exploit?id=1A36437B-B0EE-58F5-B697-1EF2282390D5
# s2-062  
Remote code execution for S2-062 CVE-2021-31805 – Verification POC  

**Verification Method**  
![Image](https://user-images.githubusercontent.com/75877299/163505291-bb028a4f-19dd-4133-a82d-89c8032cecbc.png)  
![Image](https://user-images.githubusercontent.com/75877299/163513359-934f75f9-7022-4599-bcc7-d78fbb39f74a.png)  

**Vulfocus Sandbox Issues**  
The POC verifies the S2-061 sandbox. The parameter is `id`; for the new sandbox, the parameter is `name`.  
The reason for using `id` is that it’s difficult to come up with any common commands on Windows and Linux that can serve as verification features.  
Since there is no output from the sandbox, the command itself cannot be seen.  
However, shell reverse-shell attacks and Dnslog reconnaissance are possible.  
![Image](https://user-images.githubusercontent.com/75877299/163654319-15c45139-121b-470f-acd4-3fde0631d539.png)  
![Image](https://user-images.githubusercontent.com/75877299/163654325-9b3df7c7-e528-4fe4-b0d1-0b6687ce9700.png)  

**For cases where there is no output:**  
![Image](https://user-images.githubusercontent.com/75877299/163706557-95fdbc8b-cc08-492d-9650-d8499c7c3111.png)  
![Image](https://user-images.githubusercontentCom/75877299/163706568-4bc8508a-3cf2-4dca-aebb-d198fd64e8af.png)

[source-iocs-preserved url=https://user-images.githubusercontent.com/75877299/163706568-4bc8508a-3cf2-4dca-aebb-d198fd64e8af.png]