Security for everyone

CVE-2017-9805 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Apache Software Foundation Struts  affects v. before 2.3.34 and 2.5.x before 2.5.13.

SCAN NOW

Short Info


Level

High

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

15 sec

Scan only one

Url

Parent Category

CVE-2017-9805 Scanner Detail

Apache Struts is an open-source web application framework developed in Java that is extremely popular across the world. The framework is used to build Java web applications, which operate on the Model-View-Controller (MVC) principle. The Struts framework provides developers with a robust and flexible infrastructure for developing web applications, with many advanced features enabling them to create highly dynamic pages and advanced applications with ease.

The CVE-2017-9805 vulnerability was detected in Apache Struts versions 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13. The vulnerability allowed hackers to remotely execute code because of the lack of type filtering in the XStreamHandler. Hackers could exploit the vulnerability to inject malicious code into XML payloads, which could then be decoded to run code on the server.

When this vulnerability is exploited, attackers could use it to take over the complete application, and thus access sensitive information, steal login credentials, or even alter files on the server. Attackers could even utilize the vulnerability to distribute malware to other systems or execute DDoS attacks.

Securityforeveryone.com is a comprehensive security platform that can help users protect their digital assets easily and quickly. If you're concerned about vulnerabilities in your digital assets, check out securityforeveryone.com today. Their pro features enable you to run vulnerability checks across your entire network. It will help identify and remediate any issues and provide helpful alerts across your entire IT infrastructure. Their team can proactively monitor your security posture continuously, ensuring no potential issues go undetected.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture