A Struts2 2.3.15 application, vulnerable to S2-016 (CVE-2013-2251): a parameter named redirect:, redirectAction: or action: followed by ${...} is evaluated as an OGNL expression, which runs commands.
Pas commencéDockercommit 4607d1dx86_64 · aarch64Secret
Exploit S2-016 to run commands on the Struts2 server and get a shell.
Le brief de ce lab se trouve dans son dépôt.