cve-2017-5638

1 article
sort: new top best
clear filter
0 5/10

Researcher exploited CVE-2017-5638 (Apache Struts2 RCE) in a Yahoo application by discovering a vulnerable .do endpoint and bypassing the WAF using a specially crafted Content-Type header payload, earning a $5,500 bounty from Yahoo through HackerOne.

CVE-2017-5638 Apache Struts2 Yahoo Selligent Messages Studio HackerOne Th3G3nt3lman
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 8 hours ago · details