{ "Name": "Struts2 S2-016 RCE (CVE-2013-2251)", "Description": "Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.", "Product": "Struts2", "Homepage": "http://struts.apache.org/", "DisclosureDate": "2014-09-25", "Author": "LubyRuffy@gmail.com", "FofaQuery": "app=\"Struts2\"", "GobyQuery": "app=\"Struts2\"", "Level": "3", "Impact": "A remote user can execute arbitrary code on the target system.", "Recommendation": "", "References": [ "https://cwiki.apache.org/confluence/display/ww/s2-016", "http://archiva.apache.org/security.html", "http://cxsecurity.com/issue/WLB-2014010087", "http://seclists.org/fulldisclosure/2013/Oct/96", "http://seclists.org/oss-sec/2014/q1/89", "http://struts.apache.org/release/2.3.x/docs/s2-016.html", "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2", "http://www.fujitsu.com/global/support/software/security/products-f/interstage-bpm-analytics-201301e.html", "http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html", "http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html", "http://www.securityfocus.com/bid/61189", "http://www.securityfocus.com/bid/64758", "http://www.securitytracker.com/id/1029184", "http://www.securitytracker.com/id/1032916", "https://exchange.xforce.ibmcloud.com/vulnerabilities/90392", "https://nvd.nist.gov/vuln/detail/CVE-2013-2251", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2251" ], "GifAddress": " https://raw.githubusercontent.com/gobysec/GobyVuls/master/Struts2/S2-016(CVE-2013-2251)/S2-016.gif", "HasExp": true, "ExpParams": [ { "name": "cmd", "type": "input", "value": "whoami", "show": "" } ], "ExpTips": { "Type": "Tips", "Content": "" }, "ScanSteps": null, "ExploitSteps": null, "Tags": [ "rce" ], "CVEIDs": [ "CVE-2013-2251" ], "CVSSScore": "9.3", "AttackSurfaces": { "Application": null, "Support": null, "Service": null, "System": null, "Hardware": null } }