Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
s2-067-CVE-2024-53677 — Exploit for CVE-2024-53677, a critical file upload path traversal vulnerability in Apache Struts 2.0.0-6.3.0.2 enabling remote code execution. | Kitploit
Tools/GitHubGitHub/cloudwafs/s2-067-cve-2024-53677
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubcloudwafs/s2-067-cve-2024-53677

s2-067-CVE-2024-53677

Exploit for CVE-2024-53677, a critical file upload path traversal vulnerability in Apache Struts 2.0.0-6.3.0.2 enabling remote code execution.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
9361 year agoNot yet reviewed
Share

s2-067-CVE-2024-53677

s2-067(CVE-2024-53677) Summary File upload logic is flawed, and allows an attacker to enable paths with traversals - similar problem as reported in S2-066 Who should read this

All Struts 2 developers and users

Impact of vulnerability

Remote Code Execution

Maximum security rating

Critical

Recommendation

Upgrade to Struts 6.4.0 or greater and use Action File Upload Interceptor

Affected Software

Struts 2.0.0 - Struts 2.3.37 (EOL), Struts 2.5.0 - Struts 2.5.33, Struts 6.0.0 - Struts 6.3.0.2

Reporters

Shinsaku Nomura

CVE Identifier

CVE-2024-53677

Problem An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.

Note: application not using FileUploadInterceptor are safe.

Solution Upgrade to Struts 6.4.0 or greater and migrate to the new file upload mechanism.

Backward compatibility This change isn't backward compatible as you must rewrite your actions to start using the new Action File Upload mechanism and related interceptor. Keep using the old File Upload mechanism keeps you vulnerable to this attack.

Workaround

CVE-2024-53677 Detail Received This vulnerability has been received by the NVD and has not been analyzed.

Description File upload logic is flawed vulnerability in Apache Struts. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0, which fixes the issue. You can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067

Download Tool