Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/pentestingxroot/shellevil
Payload GenerationVulnerability AnalysisExploitationShellcodeWeb Application ExploitationPenetration Testing
GitHubpentestingxroot/shellevil

ShellEvil

Struts 2 DefaultActionMapper Interactive Shell Exploit for CVE-2013-225 [S2-016]

View Repository
109 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ShellEvil

  • Jonatas Fil (Dkr)
  • Julio Della Flora
  • Thiago Sena (THX)

Struts 2 DefaultActionMapper Interactive Shell Exploit for CVE-2013-225 [S2-016]

The Struts 2 DefaultActionMapper supports a method for short-circuit navigation state changes by prefixing parameters with "action:" or "redirect:", followed by a desired navigational target expression. This mechanism was intended to help with attaching navigational information to buttons within forms.

https://struts.apache.org/docs/s2-016.html

USO: python pwn.py http://site.com:8080/xxx.action

Demo

alt text (porshe owned :p)

Download Tool