icez

5 exploits Active since Jul 2017
CVE-2017-9791 GITHUB CRITICAL WRITEUP
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
3,480 stars
CVSS 9.8
CVE-2017-9791 GITHUB CRITICAL WRITEUP
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
14 stars
CVSS 9.8
CVE-2017-9791 NOMISEC CRITICAL WORKING POC
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVSS 9.8
CVE-2017-9791 METASPLOIT CRITICAL ruby WORKING POC
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVSS 9.8
CVE-2017-9791 EXPLOITDB CRITICAL ruby WORKING POC
Apache Struts 2.1.x-2.3.x - RCE
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVSS 9.8