Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

CVE-2017-9805

2025-04-02

The REST plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 is vulnerable to deserialization without type filtering, enabling remote code execution when deserializing XML payloads.

https://nvd.nist.gov/vuln/detail/cve-2017-9805


Links to this note

  • sysrvbotnet-imperva2024

Recent Posts

Installing C and C++ Compilers on pfSense

2026-09-05 pfsense freebsd c c++ development firewall

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.