Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
S2-045-EXP-POC-TOOLS — Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header. | Kitploit
Tools/GitHubGitHub/jas502n/s2-045-exp-poc-tools
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubjas502n/s2-045-exp-poc-tools

S2-045-EXP-POC-TOOLS

Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header.

View Repository
251925 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

#CNVD-ID CNVD-2017-02474 Release Date 2017-03-07 Hazard Level High (AV:N/AC:L/Au:N/C:C/I:C/A:C) Affected Products Apache Struts >=2.3.5, <=2.3.31 Apache Struts >=2.5, <=2.5.10 CVE ID CVE-2017-5638 Vulnerability Description Apache Struts is an open-source framework for creating enterprise Java web applications. Apache Struts2 has an S2-045 remote code execution vulnerability. Remote attackers can directly take control of the web server by exploiting this vulnerability.

#Vulnerability Type General Software/Hardware Vulnerability

#Reference URL https://cwiki.apache.org/confluence/display/WW/S2-045 Vulnerability Solution Apache Struts official has fixed this vulnerability in the released new versions. Users of the Jakarta Multipart parser module are advised to upgrade to Apache Struts version 2.3.32 or 2.5.10.1: #https://cwiki.apache.org/confluence/display/WW/S2-045

#Summary Possible Remote Code Execution when performing file upload based on Jakarta Multipart parser. Who should read this All Struts 2 developers and users Impact of vulnerability Possible RCE when performing file upload based on Jakarta Multipart parser Maximum security rating High Recommendation Upgrade to Struts 2.3.32 or Struts 2.5.10.1 Affected Software:Struts 2.3.5 - Struts 2.3.31, Struts 2.5 - Struts 2.5.10 Reporter Nike Zheng dot zheng at dbappsecurity dot com dot cn> CVE Identifier CVE-2017-5638 Problem It is possible to perform a RCE attack with a malicious Content-Type value. If the Content-Type value isn't valid an exception is thrown which is then used to display an error message to a user. Solution If you are using Jakarta based file upload Multipart parser, upgrade to Apache Struts version 2.3.32 or 2.5.10.1. You can also switch to a different implementation of the Multipart parser. Backward compatibility No backward incompatibility issues are expected. Workaround Implement a Servlet filter which will validate Content-Type and throw away request with suspicious values not matching multipart/form-data.

Download Tool