Sploitus

Exploit for Deserialization of Untrusted Data in Apache Struts

githubexploit Β· 2017-09-07

Exploit Code

README9 lines
## https://sploitus.com/exploit?id=EB9CACFF-2FC5-576C-AC49-FD38C9EBD1B7
# Struts2 Vulnerability - CVE-2017-9805

## Description
Apache Struts2 REST Plugin XStream RCE(CVE-2017-9805)

## Usage
    Usage: cve_2017_9805_poc.rb [target_uri] [cmd]
    #> ruby cve_2017_9805_poc.rb 127.0.0.1 ping -c 4 192.168.0.1