Sploitus

Exploit for CVE-2018-11776

githubexploit · 2018-08-27

Exploit Code

README11 lines
## https://sploitus.com/exploit?id=A27D9B84-1FC4-5703-B4D2-2713BB4CD3E5
# Strutter

Proof of Concept for CVE-2018-11776, comes complete with the ability to search Shodan API for targets

# CVE-2018-11776

> Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution 
when using results with no namespace and in same time, its upper action(s) have no or wildcard 
namespace. Same possibility when using url tag which doesn't have value and action set and in same time, 
its upper action(s) have no or wildcard namespace.