
CVE-2017-9805: Apache Struts 2 S2-052 RCE Exploit - PoC for Harvard University (OTD)
Bu depo, Apache Struts 2 (S2-052) üzerindeki XStream deserialization zafiyetine yönelik teknik detayları ve PoC (Proof of Concept) çalışmasını içermektedir.
http://otd.harvard.edu/contact-us/)Bu zafiyet, Apache Struts REST eklentisinin XML verilerini işlerken XStream kütüphanesini güvensiz bir şekilde kullanmasından kaynaklanır. Saldırganlar, özel olarak hazırlanmış bir XML isteği göndererek sunucu üzerinde tam yetkiyle komut çalıştırabilirler.
Bu içerik sadece eğitim ve etik hacking amaçlıdır. İzin alınmamış sistemlerde kullanılması yasal sorumluluk doğurabilir. Tüm sorumluluk kullanıcıya aittir.
Bu proje MIT lisansı ile korunmaktadır.
This repository contains technical details and a Proof of Concept (PoC) for the XStream deserialization vulnerability in Apache Struts 2 (S2-052).
http://otd.harvard.edu/contact-us/)This vulnerability arises from the unsafe use of the XStream library within the Apache Struts REST plugin when processing XML data. An attacker can execute arbitrary commands on the server by sending a specially crafted XML request.
This content is for educational and ethical hacking purposes only. Unauthorized use on systems without prior consent is illegal. The user assumes all responsibility for their actions.
This project is licensed under the MIT License.