Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-5638 — Struts02 s2-045 exploit program | Kitploit
Tools/GitHubGitHub/0x00-0x00/cve-2017-5638
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHub0x00-0x00/cve-2017-5638

CVE-2017-5638

Struts02 s2-045 exploit program

View Repository
648 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-5638 | Struts s2-045

Description

It is possible to perform a RCE attack with a malicious Content-Type value. If the Content-Type value isn't valid an exception is thrown which is then used to display an error message to a user.

Affected versions

  • Struts 2.3.5
  • Struts 2.3.31
  • Struts 2.5
  • Struts 2.5.10

Exploitation

Remediation

To remediate this issue, update the affected software to apply the security patch.

Struts 2.3.32 or 2.5.10.1 are versions that are patched against this particular issue.

Author

This exploit program was written by zc00l (ANDRE LUIS .. MARQUES);

In case of modification or use, the credits must not be stripped from the work.

Resource

https://cwiki.apache.org/confluence/display/WW/S2-045

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5638

Download Tool