Strutting your stuff – Unauthenticated Remote Code Execution
ID: b19c6ad6-02f5-5e4b-8fd6-394340a0a8fb
STIX ID: report--b19c6ad6-02f5-5e4b-8fd6-394340a0a8fb
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post documents a working proof-of-concept exploit for CVE-2017-5638 in Apache Struts that enables unauthenticated remote code execution. It provides step-by-step usage examples for running the Python exploit against action pages (including targeting specific IPs), notes adjustments to bypass SSL certificate errors, and reminds defenders to patch vulnerable systems promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
