Apache Struts 2.3.28 Dynamic Method Invocation Remote Code Execution
Posted by deepcore on April 30, 2016 – 2:07 pm
This Metasploit module exploits a remote command execution vulnerability in Apache Struts version between 2.3.20 and 2.3.28 (except 2.3.20.2 and 2.3.24.2). Remote Code Execution can be performed via method: prefix when Dynamic Method Invocation is enabled.
Post a reply
You must be logged in to post a comment.