apache struts 2 s2-057 does not return shell? [on hold]
I do a pentest for a private server protected by Cloudflare. I bypassed the WAF and got the real IP for the server, then I scanned it with Acunetix and I found:
Apache Struts2 Remote Command Execution (S2-052)
> POST /ar/… Continue reading apache struts 2 s2-057 does not return shell? [on hold]