A Struts2 2.0.1 application, vulnerable to S2-001 (CVE-2007-4556): when form validation fails, the redisplayed value goes through altSyntax evaluation, so %{...} in a field runs an OGNL expression and, from there, commands.
Not startedDockercommit 5a37ffcx86_64 · aarch64Secret
Exploit S2-001 to run commands on the Struts2 server and read the flag.
The brief for this lab lives in its repository.