Top 10 winner
Multiple vulnerabilities in Apache Struts2 and property oriented programming with Java
A blackbox test where ?id=abc'+a+'def returned null exposed OGNL evaluation in Struts2 parameter names. The author shows the character whitelist still permits dynamic names and list indexes, giving constructor calls and arbitrary file overwrite via FileWriter, then chains single-argument constructors and setters found by regex across Apache Commons into file upload, which he calls property oriented programming.
Record
- Published by
- Reiners' Weblog
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Reiners' Weblog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .