CVE-2017-9805 POC# CVE-2017-9805
CVE-2017-9805 POC
The issue comes from a lack of filtering on the deserialization class used by the REST plugin. Struts uses Xstream with a lot of filtering for deserialization in multiple places, however this filtering was not in place for the REST plugin.
[4.0K] /data/pocs/3a90191e111a101fda26a494bd82692136308fb9
├── [3.1K] CVE-2017-9805.py
└── [ 275] README.md
0 directories, 2 files