struts2 CVE-2013-2251 S2-016 action、redirect code injection remote command execution
catalog
1. Description
2. Effected Scope
3. Exploit Analysis
4. Principle Of Vulnerability
5. Patch Fix
1. Description
struts2中有2个导航标签(action、redirect),后面可以直接跟ongl表达式,比如
1. test.act