Sploitus

Exploit for CVE-2018-11776

githubexploit · 2018-08-24

Exploit Code

README24 lines
## https://sploitus.com/exploit?id=45A83AEC-FD32-562F-92D6-FF5551C24CD2
# CVE-2018-11776

On August 23, 2018, Apache Struts2 released a latest security bulletin. Apache Struts2 has a high-risk vulnerability related to remote code execution. This vulnerability was reported by security researchers from Semmle Security Research. The vulnerability is identified as CVE-2018-11776 (S2-057). In Struts2, remote code execution can occur if the namespace value is not set, and if the namespace in the Action Configuration is not set or uses wildcard namespaces. **Affected versions**

Struts 2.3 to 2.3.34

Struts 2.5 to 2.5.16

**Fixed versions**

Struts 2.3.35

Struts 2.5.17

**Usage method**

python3 s2-057.py {url} Example: python3 s2-057.py http://example.com

**Vulnerability detection**

The Seebug.org online detection platform detected that a certain website has the struts S2-057 vulnerability.

The s2-057.py tool detected that a certain website has the struts S2-057 vulnerability.