Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 远程代码执行 - Shell脚本
Apache Struts 2 2.3.x 版本在 2.3.32 之前以及 2.5.x 版本在 2.5.10.1 之前,其 Jakarta Multipart 解析器在文件上传尝试期间存在不正确的异常处理和错误消息生成,允许远程攻击者通过构造 Content-Type、Content-Disposition 或 Content-Length HTTP 头来执行任意命令,正如 2017 年 3 月在野外利用中所见,攻击者使用包含 #cmd= 字符串的 Content-Type 头。
./cve-2017-5638.sh <url> <cmd>
