Add S2-016(CVE-2013-2251)

This commit is contained in:
tardc 2020-04-13 14:43:32 +08:00
parent f59f993886
commit 2e0671dd95
2 changed files with 11 additions and 0 deletions

View File

@ -0,0 +1,11 @@
# S2-016 (CVE-2013-2251) Remote Code Execution Vulnerability
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Affected Version: Apache Struts2 2.0.0 - 2.3.15
FOFA query rule: app="Struts2"
# Demo
![](S2-016.gif)

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.7 MiB