CVE-2012-1592
HIGHApache Struts 2.0-2.5.22 - Unrestricted Upload of File with Dangerous Type via Malformed XSLT Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1592. PoCs published by voidloafer.
AI-analyzed exploit summary This exploit leverages a remote arbitrary file-upload vulnerability in Apache Struts2 by using OGNL injection to execute arbitrary commands (e.g., 'calc') via an XSL stylesheet. The vulnerability arises from insufficient input sanitization, allowing attackers to run code in the context of the webserver process.
Description
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
Exploits (1)
This exploit leverages a remote arbitrary file-upload vulnerability in Apache Struts2 by using OGNL injection to execute arbitrary commands (e.g., 'calc') via an XSL stylesheet. The vulnerability arises from insufficient input sanitization, allowing attackers to run code in the context of the webserver process.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H