漏洞描述 Apache Struts2 S2-067漏洞是由于框架对特定请求处理不当导致的远程代码执行漏洞。攻击者可通过精心构造的恶意请求,利用/index.action路径上传恶意文件或执行任意代码。该漏洞主要影响未正确配置或使用过时版本的Struts2应用,尤其在文件上传功能中未严格过滤用户输入时风险加剧。
相关漏洞推荐 POCCVE-2007-4556: OpenSymphony XWork/Apache Struts2 - Remote Code Execution S2-001 POCCVE-2012-0392: Apache Struts2 S2-008 RCE POCCVE-2013-1965: Apache Struts2 S2-012 RCE POCCVE-2017-12611: Apache Struts2 S2-053 - Remote Code Execution POCCVE-2017-9791: Apache Struts2 S2-053 RCE POCCVE-2018-11776: Apache Struts2 S2-057 - Remote Code Execution POCCVE-2021-31805: Apache Struts2 S2-062 RCE 无POCApache Struts2 2.0.0~2.2.3 S2-007 /user.action 命令执行漏洞(CVE-2012-0838) POCCVE-2007-4556: OpenSymphony XWork/Apache Struts2 - Remote Code Execution POCCVE-2012-0392: Apache Struts2 S2-008 RCE POCCVE-2013-1965: Apache Struts2 S2-012 RCE POCCVE-2017-12611: Apache Struts2 S2-053 - Remote Code Execution POCCVE-2017-9791: Apache Struts2 S2-053 - Remote Code Execution