EIP-2026-102356
PRE-CVEApache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102356. PoCs published by Jonatas Fil.
AI-analyzed exploit summary This Python script exploits CVE-2013-2251 (S2-016) in Apache Struts 2 by leveraging the DefaultActionMapper's OGNL injection vulnerability to achieve remote code execution. It constructs a malicious URL with OGNL payloads to execute arbitrary commands on the target system.
Description
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
Exploits (1)
This Python script exploits CVE-2013-2251 (S2-016) in Apache Struts 2 by leveraging the DefaultActionMapper's OGNL injection vulnerability to achieve remote code execution. It constructs a malicious URL with OGNL payloads to execute arbitrary commands on the target system.