| Title | ListSERV Maestro <= 9.0-8 RCE |
|---|---|
| Author | b0yd |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Upgrade to a patched version of ListSERV Maestro that is not affected by this vulnerability. |
| CVSS Score | 5 |
| EPSS Score | 0.9341 |
| CVE ID | CVE-2010-1870 |
| CWE ID | CWE-917 |
| Shodan Query | http.html:"apache struts"http.title:"struts2 showcase"http.html:"struts problem report" |
| Fofa Query | body="struts problem report"title="struts2 showcase"body="apache struts" |
| Tags | cve cve2010 packetstorm edb rce listserv ognl apache vuln |
A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
GET /lui/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /hub/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-1870.yaml
🦈 Packet Capture: ⬇️ Download cve-2010-1870.pcap
N/AN/A