CVE-2017-9791

Apache Struts 1 Improper Input Validation Vulnerability

9.8
CVSS 3.1
98.9 %
EPSS (current)
2022-02-10
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Apache / Struts 1

Published: 2017-07-10 · Due (CISA): 2022-08-10

CWE: CWE-20 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2017/CVE-2017-9791.yamlApache Struts2 S2-053 - Remote Code Execution–
exploitdb42324Apache Struts 2.3.x Showcase - Remote Code Execution2017-07-07
metasploitexploit/multi/http/struts2_code_exec_showcaseexploit/multi/http/struts2_code_exec_showcase2017-07-07
exploitdb44643Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)2018-05-17

References only — no downloads or instructions.

Sources