Exploit for CVE-2021-31805 (RCE in Apache Struts 2)
Copy link to “Exploit for CVE-2021-31805 (RCE in Apache Struts 2)”Sniper can now exploit an RCE vulnerability in Apache Struts 2 (CVE-2021-31805).
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
Sniper can now exploit an RCE vulnerability in Apache Struts 2 (CVE-2021-31805).
Sniper can now exploit an RCE vulnerability in Redis (CVE-2022-0543).
Sniper can now exploit an RCE vulnerability in the VMware Workspace ONE Access (CVE-2022-22954).
Sniper can now exploit an unauthenticated RCE vulnerability in Magento (CVE-2022-24086).
Sniper can now exploit an RCE vulnerability in Spring Cloud Function - a library in Spring (CVE-2022-22963).
Sniper can now exploit an RCE vulnerability in Spring core - a main component of the Java Spring Framework (CVE-2022-22965 - Spring4Shell).
Website Scanner findings that haven't been automatically validated by our scanner and need further manual verification will be marked with the 'Unconfirmed' tag.
The Domain Finder tool can now be accessed via the API.
Sniper can now authenticate to the target service using the provided credentials. Then it will extract the artefacts as an authenticated user.
Sniper can now exploit an RCE vulnerability in Spring Cloud Gateway (CVE-2022-22947).
The Domain Finder assigns a certain weight (or certainty) to each result to validate its correctness. Now the value of this parameter can be set to better filter the results.
Sniper can now exploit an RCE in the Apache Struts Framework (CVE-2017-12611).
The Network Scanner can now detect if an Oracle Weblogic Server is vulnerable to an Authentication Bypass vulnerability (CVE-2020-14882, CVE-2020-14883).
Added the possibility to chain the Domain Finder tool within the Pentest Robots.
Sniper can now exploit an RCE in the Log4j logging library from Apache Struts 2 (CVE-2021-44228).
Sniper can now exploit an Authentication Bypass and RCE vulnerability in Zoho ManageEngine Desktop Central (CVE-2021-44515).
Sniper can now exploit an RCE in the Log4j logging library (CVE-2021-45046).
Sniper can now exploit an Authentication Bypass leading to Remote Code Execution in Zabbix (CVE-2022-23131).
Choose your own wordlist or pick from the default ones in order to uncover new subdomains by trying each of them in the DNS Enumeration method of the Subdomain Finder.
The Network Scanner can now detect if a Microsoft Windows instance is vulnerable to EternalBlue (CVE-2017-0144).