
Apache Struts CVE-2017-5638 RCE exploitation
:source-highlighter: pygments
= Apache Struts CVE-2017-5638 exploitation
This simple web application is built with vulnerable Apache Struts 2.5.10 (CVE-2017-5638). It's vulnerable to RCE.
== Starting web application
8012 by default. You can change it:== Accessing web application
To access the vulnerable web application, open the following link in your browser: http://127.0.0.1:8012/struts-rce. If you changed the default port, modify the link accordingly.
== Exploiting web application
Content-Typeidid command on the server side:
[source,bash]cat /etc/passwd:
[source,bash]