CVE-2013-1966
Apache Struts 2.0.0-2.3.14.1 - Remote Code Execution via OGNL Injection in URL/A Tag
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-1966.
PoCs published by Coverity security Research Laboratory, NSFOCUS Security Team, Eric Kobrin, Douglas Rodrigues, including Metasploit module exploits/multi/http/struts_include_params.
AI-analyzed exploit summary This Metasploit module exploits CVE-2013-1966, a remote code execution vulnerability in Apache Struts versions < 2.3.14.2. It leverages OGNL injection via crafted request parameters to bypass protections and execute arbitrary commands, supporting multiple platforms (Windows, Linux, Java).
Description
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.
Exploits (2)
This Metasploit module exploits CVE-2013-1966, a remote code execution vulnerability in Apache Struts versions < 2.3.14.2. It leverages OGNL injection via crafted request parameters to bypass protections and execute arbitrary commands, supporting multiple platforms (Windows, Linux, Java).
This Metasploit module exploits CVE-2013-1966, a remote code execution vulnerability in Apache Struts versions < 2.3.14.2. It leverages OGNL injection to bypass protections and execute arbitrary commands by manipulating the `includeParams` feature.