Tag
critical
advisory
Critical RCE Vulnerability in Apache Struts (S2-067)
1 rule 2 TTPs 1 CVEA critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.
Struts
apache-struts
rce
file-upload
web-application-attack
1r
2t
1c
high
advisory
Apache Struts CVE-2023-50164 Exploitation Leading to Web Shell Deployment
2 rules 3 TTPs 1 CVEExploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2, is detected by identifying malicious multipart/form-data POST requests with WebKitFormBoundary targeting Struts .action upload endpoints, followed by JSP web shell creation in Tomcat's webapps directories, indicating remote code execution.
Struts 2
apache-struts
webshell
cve-2023-50164
initial-access
persistence
command-and-control
2r
3t
1c