
CVE-2017-5638 示例 PoC 代码 | Apache Struts 漏洞利用
CVE-2017-5638 的示例概念验证代码 | Apache Struts 漏洞利用 | DORK: ext:action
USAGE: python struts.py https://victim.site dir
最初发布的 Python 脚本未正确格式化 Content-Type 标头。 我重新编写了 Content-Type 标头,使其正确格式化为 Content-Type:%20{Exploit}。 我还添加了日志记录和 Requests 库,并将对象属性输出到标准输出。
示例输出
Check for CVE-2017-5638 by XSS.Cx
Volume in drive D has no label. Volume Serial Number is 2A7B-A245 Directory of d:\Program Files\Apache Software Foundation\Tomcat 9.0