漏洞描述
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
struts.apache.orghttp://struts.apache.org/development/2.x/docs/s2-012.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2013-1965↗bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=967655↗github.comhttps://github.com/CrackerCat/myhktools↗github.comhttps://github.com/GhostTroops/myhktools↗