Web Hack List

Top 10 winner

Multiple vulnerabilities in Apache Struts2 and property oriented programming with Java

A blackbox test where ?id=abc'+a+'def returned null exposed OGNL evaluation in Struts2 parameter names. The author shows the character whitelist still permits dynamic names and list indexes, giving constructor calls and arbitrary file overwrite via FileWriter, then chains single-argument constructors and setters found by regex across Apache Commons into file upload, which he calls property oriented programming.

Record

Published by
Reiners' Weblog
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Reiners' Weblog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .