Web Hack List

Top 10 winner

Apache Struts ClassLoader Manipulation Remote Code Execution

The Struts S2-020 bulletin covers two issues fixed in 2.3.16.1: Commons FileUpload 1.3 allows denial of service, and ParametersInterceptor accepts a class parameter mapped to getClass(), letting a remote attacker manipulate the ClassLoader. The advised remedies are upgrading the library and excluding class from request parameters.

Record

Researcher
Lukasz Lenart
Published by
cwiki.apache.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Lukasz Lenart, first published at the original source. Preserved copies are kept so the citation survives its host.