{"id":19521085,"url":"https://github.com/xsscx/cve-2017-5638","last_synced_at":"2025-04-26T08:31:16.743Z","repository":{"id":90329262,"uuid":"84581800","full_name":"xsscx/cve-2017-5638","owner":"xsscx","description":"Example PoC Code for CVE-2017-5638 | Apache Struts Exploit ","archived":false,"fork":false,"pushed_at":"2017-03-12T15:43:27.000Z","size":21,"stargazers_count":19,"open_issues_count":0,"forks_count":21,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-04-04T10:04:55.127Z","etag":null,"topics":["apache","code","content-type","cve-2017-5638","exploit","poc","python","struts2"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/xsscx.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-03-10T16:56:14.000Z","updated_at":"2025-01-12T14:52:42.000Z","dependencies_parsed_at":null,"dependency_job_id":"8405e875-9850-4661-8ba3-60ebc0dc100e","html_url":"https://github.com/xsscx/cve-2017-5638","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xsscx%2Fcve-2017-5638","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xsscx%2Fcve-2017-5638/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xsscx%2Fcve-2017-5638/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xsscx%2Fcve-2017-5638/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/xsscx","download_url":"https://codeload.github.com/xsscx/cve-2017-5638/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250959641,"owners_count":21514304,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["apache","code","content-type","cve-2017-5638","exploit","poc","python","struts2"],"created_at":"2024-11-11T00:29:14.492Z","updated_at":"2025-04-26T08:31:16.738Z","avatar_url":"https://github.com/xsscx.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2017-5638 PoC Code in Python | DORK: ext:action\nExample PoC Code for CVE-2017-5638 | Apache Struts Exploit | DORK: ext:action\n\nUSAGE: python struts.py https://victim.site dir\n\nThe initial Python Script that was Posted didn't correctly format the Content-Type Header.\nI recoded the Content Type Header to properly format Content-Type:%20{Exploit}.\nI also added a logging and Requests, then dumped the Object Properties to stdout.\n\nSAMPLE OUTPUT\n\nCheck for CVE-2017-5638 by XSS.Cx\n\nVolume in drive D has no label.\nVolume Serial Number is 2A7B-A245\nDirectory of d:\\Program Files\\Apache Software Foundation\\Tomcat 9.0\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxsscx%2Fcve-2017-5638","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fxsscx%2Fcve-2017-5638","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxsscx%2Fcve-2017-5638/lists"}