May 22, 2012, 09:45:40 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: THC is up and running !
 

 
advertisement:

Pages: [1]
  Print  
Author Topic: RSS: Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution  (Read 20 times)
zomgwtfbbq
Challenge Coder
Administrator
Hero Member
*****

Karma: +31340/-1
Posts: I am a geek!!


thc title: thc elite
thc points: 3315
challenges: (69/83)

View Profile
« on: February 07, 2012, 12:25:07 AM »
Share on FacebookFacebook Share

Apache Struts ParameterInterceptor Class OGNL Expression Parsing Remote Command Execution


Synopsis :

A remote web application uses a framework that has a code execution
vulnerability.

Description :

The remote web application appears to use Struts 2, a web framework
that uses XWork. Due to a flaw in the ParameterInterceptor class,
user input is not properly sanitized, which could allow a remote
attacker to run arbitrary Java code on the remote host by sending a
specially crafted HTTP request.

See also :


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://blog.o0o.nu/2012/01/cve-2011-3923-yet-another-struts2.html


only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
https://cwiki.apache.org/confluence/display/WW/S2-009


Solution :

Upgrade to Struts 2.3.1.2 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)



original thread:
only registered users with at least 25 hack challenge points can see links:
click here in order to visit the hack challenges
http://www.nessus.org/plugins/index.php?view=single&id=57850
Logged


only registered users with at least 25 hack challenge points can see links:
  click here in order to visit the hack challenges


Ook al ben ik een slet toch houdt ik van je..
Pages: [1]
  Print  
 
Jump to:  


SMF Board hacked and modded by zomgwtfbekjam aka Rembo from Tools & Design