logo

Strutting your stuff – Unauthenticated Remote Code Execution

ID: b19c6ad6-02f5-5e4b-8fd6-394340a0a8fb

STIX ID: report--b19c6ad6-02f5-5e4b-8fd6-394340a0a8fb

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2017-03-10

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post documents a working proof-of-concept exploit for CVE-2017-5638 in Apache Struts that enables unauthenticated remote code execution. It provides step-by-step usage examples for running the Python exploit against action pages (including targeting specific IPs), notes adjustments to bypass SSL certificate errors, and reminds defenders to patch vulnerable systems promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.