Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-5638 — An exploit for CVE-2017-5638 | Kitploit
Tools/GitHubGitHub/mritunjay-k/cve-2017-5638
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubmritunjay-k/cve-2017-5638

CVE-2017-5638

An exploit for CVE-2017-5638

View Repository
1323 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-5638

The Apache Struts 2 versions 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 have a flaw in their Jakarta Multipart parser. This flaw causes incorrect handling of exceptions and generation of error messages when attempting to upload files. As a result, attackers can remotely execute arbitrary commands by exploiting a crafted HTTP header such as Content-Type, Content-Disposition, or Content-Length.

Execution

python exploit.py -r <rhost-url> -c <desired-command>

poc

Reference

NIST NVD MITRE Corporation

Download Tool