Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
strutt-cve-2014-0114 — Technical analysis and proof-of-concept for Apache Struts 1 class parameter manipulation (CVE-2014-0114), demonstrating remote code execution on Tomcat and denial-of-service on JBoss/Wildfly. | Kitploit
Tools/GitHubGitHub/aenlr/strutt-cve-2014-0114
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPapers & ResearchLearning & Education
GitHubaenlr/strutt-cve-2014-0114

strutt-cve-2014-0114

Technical analysis and proof-of-concept for Apache Struts 1 class parameter manipulation (CVE-2014-0114), demonstrating remote code execution on Tomcat and denial-of-service on JBoss/Wildfly.

View Repository
21577 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2014-0114 - Vulnerability in Struts 1

Parameters in a POST or GET request are handled as properties to be set with the form as a starting point. Parameters can be a path to a nested object.

Apache Struts 1.x can be manipulated to call getClass() on Form Beans. For example, one can directly manipulate attributes on the form's classloader: https://example.com/?class.classLoader.defaultAssertionStatus=true.

Under the hood, Apache Struts 1.x uses commons-beanutils which in version 1.8 (and earlier) does not exclude the class attribute.

Struts 2 has had similar flaws, but here we focus on Struts 1.x where there are no patches to the framework whose latest version was released in 2008 (EOL since 2013).

Tomcat - Remote Code Execution (RCE)

If the application runs on Tomcat (Catalina), logging can be manipulated so that the attacker can create a JSP file which is then executed when requested from the server. The JSP file can execute arbitrary Java code as the user running the Java process.

See Julián Vila's demonstration for details.

JBoss/Wildfly - Denial Of Service (DOS)

(Tested with JBoss EAP 7.1)

There is a simple method to perform a DOS attack that in the worst case makes JBoss completely unreachable and requires a restart. In the best case, JBoss responds slowly.

Execution

Through the class attribute it is possible to access Class#protectionDomain.codeSource.location. In JBoss, this is a URL object with the vfs protocol.

For a URL of type vfs://, JBoss has registered a URLStreamHandler that returns an object of type org.jboss.vfs.VirtualFile when URL#getContent is called.

class.protectionDomain.codeSource.location.content.pathName points to the directory <PATH>/<application>/WEB-INF/classes.

Via parent you access an object for the directory one level up:

class.protectionDomain.codeSource.location.content.parent.pathName -> <PATH>/<application>/WEB-INF

Question: How many parent references are needed to reach the root of the filesystem?

Question: What happens when we request class.protectionDomain.codeSource.location.content.parent.parent.[...].childrenRecursively[0].pathName for the filesystem's root directory?

Answer: JBoss will go through all files in the filesystem and allocate an org.jboss.vfs.VirtualFile for each file and directory.

Follow-up question: What happens if two requests request all files in the filesystem simultaneously? Three requests? Five? Ten? One hundred?

...

Answer:

If you wait long enough, an error is logged

Download Tool