mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-01 06:51:35 +02:00
52 lines
2.4 KiB
Markdown
52 lines
2.4 KiB
Markdown
### [CVE-2021-31805](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31805)
|
||

|
||

|
||
&color=brighgreen)
|
||
|
||
### Description
|
||
|
||
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://www.oracle.com/security-alerts/cpujul2022.html
|
||
|
||
#### Github
|
||
- https://github.com/0day404/vulnerability-poc
|
||
- https://github.com/20142995/Goby
|
||
- https://github.com/3SsFuck/CVE-2021-31805-POC
|
||
- https://github.com/ARPSyndicate/cvemon
|
||
- https://github.com/ARPSyndicate/kenzer-templates
|
||
- https://github.com/ArrestX/--POC
|
||
- https://github.com/Awrrays/FrameVul
|
||
- https://github.com/Axx8/Struts2_S2-062_CVE-2021-31805
|
||
- https://github.com/HimmelAward/Goby_POC
|
||
- https://github.com/KayCHENvip/vulnerability-poc
|
||
- https://github.com/Miraitowa70/POC-Notes
|
||
- https://github.com/Mr-xn/Penetration_Testing_POC
|
||
- https://github.com/NaInSec/CVE-PoC-in-GitHub
|
||
- https://github.com/SYRTI/POC_to_review
|
||
- https://github.com/Threekiii/Awesome-POC
|
||
- https://github.com/WhooAmii/POC_to_review
|
||
- https://github.com/Wrin9/CVE-2021-31805
|
||
- https://github.com/Z0fhack/Goby_POC
|
||
- https://github.com/aeyesec/CVE-2021-31805
|
||
- https://github.com/d4n-sec/d4n-sec.github.io
|
||
- https://github.com/fleabane1/CVE-2021-31805-POC
|
||
- https://github.com/izj007/wechat
|
||
- https://github.com/jax7sec/S2-062
|
||
- https://github.com/liang2kl/iot-exploits
|
||
- https://github.com/lions2012/Penetration_Testing_POC
|
||
- https://github.com/nomi-sec/PoC-in-GitHub
|
||
- https://github.com/nth347/CVE-2021-31805
|
||
- https://github.com/nu1r/yak-module-Nu
|
||
- https://github.com/pyroxenites/s2-062
|
||
- https://github.com/trganda/starrlist
|
||
- https://github.com/trhacknon/Pocingit
|
||
- https://github.com/whoami13apt/files2
|
||
- https://github.com/xuetusummer/Penetration_Testing_POC
|
||
- https://github.com/z92g/CVE-2021-31805
|
||
- https://github.com/zecool/cve
|
||
|