The Struts2 2.5.12 REST showcase, vulnerable to S2-052 (CVE-2017-9805): the REST plugin's XStreamHandler unmarshals any XML request body, so a crafted XML payload (a gadget chain) runs commands on the server.
Pas commencéDockercommit c506052x86_64 · aarch64Secret
Exploit S2-052 with an XML body sent to the REST showcase to run commands and get a shell.
Le brief de ce lab se trouve dans son dépôt.