GobyVuls/Struts2/S2-061(CVE-2020-17530)
2020-12-16 10:39:16 +08:00
..
2020-12-16 10:39:16 +08:00
2020-12-16 10:39:16 +08:00

S2-061 (CVE-2020-17530) Remote Code Execution Vulnerability

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Affected version: Apache Struts 2.0.0 - Struts 2.5.25

FOFA query rule: app="Struts2"

Demo