CVE-2008-6504

OpenSymphony XWork 2.0.x < 2.0.6 and 2.1.x < 2.1.2 - Remote Code Execution via OGNL Context Object Reference

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6504. PoCs published by Meder Kydyraliev.

AI-analyzed exploit summary This exploit leverages a security-bypass vulnerability in XWork by manipulating server-side context objects through crafted input. It demonstrates setting a session variable to an arbitrary value, potentially compromising the application.

Description

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Meder Kydyraliev · textremotemultiple
https://www.exploit-db.com/exploits/32564

This exploit leverages a security-bypass vulnerability in XWork by manipulating server-side context objects through crafted input. It demonstrates setting a session variable to an arbitrary value, potentially compromising the application.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: XWork < 2.0.6, Struts 2.0.0 - 2.0.11.2
No auth needed
Prerequisites: Access to a vulnerable XWork/Struts application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46328
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32495
Patch x_refsource_confirm
http://fisheye6.atlassian.com/cru/CR-9/
Exploit x_refsource_confirm
http://struts.apache.org/2.x/docs/s2-003.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3003
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3004
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32101
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32497
Exploit x_refsource_confirm
http://jira.opensymphony.com/browse/XW-641
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49732

Scores

EPSS 0.6512
EPSS Percentile 98.5%

Details

CWE
CWE-20
Status published
Products (21)
apache/struts 2.0.0
apache/struts 2.0.2
apache/struts 2.0.3
apache/struts 2.0.4
apache/struts 2.0.5
apache/struts 2.0.6
apache/struts 2.0.7
apache/struts 2.0.8
apache/struts 2.0.9
apache/struts 2.0.11
... and 11 more
Published Mar 23, 2009
Tracked Since Feb 18, 2026