Apache Struts Dynamic Method Invocation Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 30 Apr 2016.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a remote command execution vulnerability in Apache Struts version between 2.3.20 and 2.3.28 (except 2.3.20.2 and 2.3.24.2). Remote Code Execution can be performed via method: prefix when Dynamic Method Invocation is enabled.

    Continue reading...
     

Share This Page

Loading...