A Struts2 2.3.15 application, vulnerable to S2-016 (CVE-2013-2251): a parameter named redirect:, redirectAction: or action: followed by ${...} is evaluated as an OGNL expression, which runs commands.
Not startedDockercommit 4607d1dx86_64 · aarch64Secret
Exploit S2-016 to run commands on the Struts2 server and get a shell.
The brief for this lab lives in its repository.