ET EXPLOIT Apache Struts RCE CVE-2018-11776 POC M2
Sourceet/open
CreatedAugust 23, 2018
UpdatedAugust 25, 2020
Classificationattempted-user
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Apache Struts RCE CVE-2018-11776 POC M2"; flow:to_server,established; http.uri; content:"memberAccess"; content:"allowStaticMethodAccess"; distance:0; content:"java.lang.Runtime@getRuntime().exec("; nocase; fast_pattern; distance:0; content:".getInputStream"; content:"java.io.InputStreamReader"; content:"java.io.BufferedReader"; content:".read"; content:"@org.apache.struts2.ServletActionContext@getResponse"; reference:url,github.com/jas502n/St2-057/blob/master/README.md; reference:cve,2018-11776; classtype:attempted-user; sid:2026026; rev:2; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2018_08_23, cve CVE_2018_11776, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_25;)
References
Metadata
affected productApache_Struts2
attack targetWeb_Server
created at2018_08_23
deploymentPerimeter
confidenceMedium
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2020_08_25
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!