Sploitus

Exploit for Deserialization of Untrusted Data in Apache Struts

githubexploit Β· 2017-09-06

Exploit Code

README25 lines
## https://sploitus.com/exploit?id=287B0891-84E7-564C-970E-283930B2A2D3
### Description

Apache Struts RCE tool for CVE 2017-9805

### Options

- `u`: the target url;
- `c`: the command that'll be executed on a vulnerable target;
- `f`: automatically checks for RCE using a list of targets (one target per line);
- `p`: specify the port for a local listener - used with `f` option - (default: 8080)

### Usage

```
go run main.go -u target -c command
```

```
go run main.go -f filename
```

```
go run main.go -f filename -p port
```