add S2-061

This commit is contained in:
tardc 2020-12-16 10:39:16 +08:00
parent 099ff419ff
commit 04c173e86f
2 changed files with 12 additions and 0 deletions

View File

@ -0,0 +1,12 @@
# S2-061 (CVE-2020-17530) Remote Code Execution Vulnerability
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
**Affected version**: Apache Struts 2.0.0 - Struts 2.5.25
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJTdHJ1dHMyIg%3D%3D) query rule**: app="Struts2"
# Demo
![](S2-061.gif)

Binary file not shown.

After

Width:  |  Height:  |  Size: 408 KiB