CVE-2018-11776 is a remote code execution vulnerability in Apache Struts 2 caused by improper validation of user-supplied namespace values during request processing. In affected Struts 2 releases, when alwaysSelectFullNamespace is enabled and the application uses results without an explicit namespace, or uses url tags without value or action under packages with no namespace or a wildcard namespace, attacker-controlled URI data can be interpreted as a namespace and reach OGNL expression evaluation. This allows a remote attacker to supply a crafted URL that triggers OGNL injection in the Struts core and execute arbitrary code in the context of the application server. Affected versions include Struts 2.3 through 2.3.34 and 2.5 through 2.5.16, with some reporting also indicating exposure across 2.0.4 through 2.3.34 and 2.5.0 through 2.5.16.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository provides a proof-of-concept exploit for CVE-2018-11776, a critical remote code execution vulnerability in Apache Struts 2. The repository contains two main exploit scripts: 'bashexploit.py' (Python) and 'bashexploit.sh' (Bash). Both scripts construct and send malicious OGNL payloads to a specified Struts 2 endpoint. The first payload disables OGNL security restrictions, and the second payload spawns a reverse shell to the attacker's machine (10.10.0.90:4747) using netcat. The Python script uses the 'requests' library to send the payloads, while the Bash script uses 'curl' and requires the target URL as an argument. The README is minimal, simply stating the CVE and that this is a PoC script. The exploit is operational and provides a working reverse shell if the target is vulnerable and accessible.
This repository contains a Python exploit script (Apache_Struts.py) targeting the Apache Struts CVE-2018-11776 remote code execution vulnerability. The exploit works by prompting the user for a target URL and then allowing the user to input arbitrary shell commands, which are executed on the remote server via a crafted OGNL payload injected into the HTTP Content-Type header. The script uses Python's urllib2 to send the malicious request and displays the command output to the user. The README provides basic usage instructions and references the critical nature of the vulnerability. The repository structure is simple, with one main exploit script, a README, and a configuration file (.whitesource) unrelated to the exploit logic. The exploit is operational, providing interactive remote code execution if the target is vulnerable.
This repository contains a single Metasploit module: 'struts2_namespace_ognl.rb', which exploits CVE-2018-11776, a remote code execution vulnerability in Apache Struts 2 (versions 2.3-2.3.4 and 2.5-2.5.16). The exploit leverages OGNL injection via a redirect action endpoint, allowing attackers to execute arbitrary commands or deploy payloads on the target server. The module is highly configurable, supporting various payload types and platforms (Windows, Linux, Unix), and includes options for customizing the HTTP method, headers, and temporary file names. The exploit is weaponized, as it is part of the Metasploit framework and supports automated payload delivery and execution. The main fingerprintable endpoints are the base path to the Struts application and the redirect action endpoint (e.g., '/showcase.action'). The module is designed for remote exploitation over HTTP and requires the attacker to specify valid application paths and endpoints.
This repository is a proof-of-concept exploit for CVE-2018-11776, a remote code execution vulnerability in Apache Struts 2 (versions 2.3 to 2.3.34 and 2.5 to 2.5.16). The main file, 'strutter.py', is a Python script that allows the user to specify a target host, a command to execute, and optionally use the Shodan API to discover vulnerable hosts on the internet. The exploit works by crafting a malicious OGNL payload that is injected into a Struts endpoint (typically '/actionChain1.action'), resulting in arbitrary command execution on the server. The script supports custom user agents, proxies, and can automate the process of finding and testing multiple targets. The repository contains a README with usage information, an empty __init__.py, and the main exploit logic in strutter.py. The exploit is operational and demonstrates real-world RCE, but does not include advanced payload customization or post-exploitation features.
This repository contains a Python exploit script (exploit.py) and a README.md for Apache Struts 2 Remote Code Execution vulnerability S2-057 (CVE-2018-11776). The exploit works by crafting a malicious OGNL expression in the URL path, which is interpreted by vulnerable Struts 2 servers, leading to arbitrary command execution. The script takes four arguments: the target URL, the command to execute, the action endpoint, and the payload variant. It supports multiple payloads for different Struts 2 versions, all leveraging OGNL injection to execute system commands via Java's Runtime.exec(). The README provides usage instructions, an example (targeting http://127.0.0.1:8080/showcase), and references for further reading. The exploit is operational, returning the output of the executed command in the HTTP response, and is intended for educational or informational purposes only.
This repository provides a working Python proof-of-concept (PoC) exploit for CVE-2018-11776, a critical remote code execution vulnerability in Apache Struts2 (versions 2.3 to 2.3.34 and 2.5 to 2.5.16). The exploit leverages OGNL injection via the URL path to achieve arbitrary command execution on the target server. The repository includes: - A Dockerfile for setting up a vulnerable Struts2 environment using Tomcat 7 and the struts2-showcase-2.3.12.war application. - A detailed README.md with setup instructions, vulnerability background, exploitation steps, and mitigation advice. - `exploitS2-057-cmd.py`: The main exploit script, which crafts a malicious OGNL payload and injects it into the URL path to execute arbitrary commands or spawn a reverse shell on the target. - `exploitS2-057-test.py`: A test script to verify if a given URL is vulnerable by checking for OGNL evaluation and redirect behavior. The exploit requires the target to be misconfigured (as described in the README), and provides both Linux and Windows command execution capabilities. The main attack vector is network-based, targeting HTTP endpoints on the vulnerable Struts2 application. The repository is operational, providing a real-world exploit with customizable payloads for post-exploitation activities.
This repository is a proof-of-concept (PoC) exploit for CVE-2018-11776, a critical remote code execution vulnerability in Apache Struts. The main script, 'Struts.py', combines Shodan search capabilities with an OGNL injection exploit to automate the discovery and exploitation of vulnerable Apache Struts servers. The tool prompts the user for a Shodan API key (stored in 'api.txt') and a command to execute on targets (default: 'id'). It uses Shodan to find servers running Apache, then tests each for the vulnerability by sending a crafted OGNL payload in the URL path. If a server is found vulnerable, the specified command is executed remotely, and the output is displayed. The repository contains three files: a Python exploit script ('Struts.py'), a README with usage instructions, and a .gitattributes file. The exploit is network-based, targeting HTTP endpoints on potentially vulnerable servers, and is intended for research and demonstration purposes only.
This repository contains a Python exploit script (struts-pwn.py) targeting Apache Struts2 installations vulnerable to CVE-2018-11776 (S2-057). The exploit works by sending specially crafted HTTP requests containing OGNL expressions that, if the target is vulnerable, result in remote command execution on the server. The script can check single URLs or lists of URLs for vulnerability and, if the '--exploit' flag is used, execute arbitrary commands on the target. The payload is injected into the URL path, exploiting the way Struts2 handles namespace resolution. The repository includes a README with usage instructions, a requirements.txt specifying the 'requests' library, and a standard MIT license. The main entry point is struts-pwn.py, which is a standalone Python script supporting both Python2 and Python3. The exploit is operational, providing real command execution if the target is vulnerable, and is not just a detection script.
This repository provides a working exploit environment and script for CVE-2018-11776 (Apache Struts2 S2-057). The structure includes a Dockerfile to set up a Tomcat 7 server with the vulnerable struts2-showcase-2.3.12.war application, a Python exploit script (exploit.py), a README with usage instructions, and a license file. The exploit.py script constructs a malicious OGNL payload and injects it into the URL path of a request to the vulnerable server, resulting in arbitrary command execution via Java's ProcessBuilder. The README demonstrates how to run the vulnerable environment in Docker and how to use the exploit to obtain a reverse shell. The main attack vector is network-based, targeting the HTTP interface of the Struts2 application. The endpoints of interest are the HTTP URL used for exploitation and the file paths involved in deploying the vulnerable application. The exploit is operational, providing a real-world demonstration of remote code execution against a configured vulnerable environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior Apache Struts vulnerability referenced as historical context because its fix introduced cleanupActionName in DefaultActionMapper, but that sanitization was not applied to RestfulActionMapper.
An Apache Struts OGNL injection remote code execution vulnerability, demonstrated here via a crafted request that executes 'cat /etc/passwd' and returns command output in the HTTP Location header during a 302 redirect.
Apache Struts 2 remote code execution vulnerability targeted in the actor’s top CVE list.
A critical remote code execution vulnerability in Apache Struts 2 (S2-057) that allows attackers to execute arbitrary commands via crafted requests due to improper namespace handling in the Struts configuration. This affects Struts 2.0.4-2.3.34 and 2.5.0-2.5.16.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.