CVE-2024-9805
published 2024-10-10CVE-2024-9805: A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.41%
33.5th percentile
A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/campsdetails.php. The manipulation of the argument hospital/address/city/contact leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "hospital".
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | blood_bank_system | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET SCAN struts-pwn User-Agent
suricata·2017-10-16·CVSS 8.1
CVE-2017-9805 [HIGH] ET SCAN struts-pwn User-Agent
ET SCAN struts-pwn User-Agent
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN struts-pwn User-Agent"; flow:established,to_server; http.user_agent; content:"struts-pwn"; startswith; fast_pattern; reference:url,github.com/mazen160/struts-pwn_CVE-2017-9805/blob/master/struts-pwn.py; reference:cve,2017-9805; reference:url,paladion.net/paladion-cyber-labs-discovers-a-new-ransomware/; classtype:attempted-user; sid:2024843; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_10_16, cve CVE_2017_9805, deployment Datacenter, performance_impact Moderate, confidence High, signature_severity Minor, tag CISA_KEV, updated_at 2024_04_12;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (ProcessBuilder)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"java.lang.ProcessBuilder"; nocase; fast_pattern; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024675; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 6"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|4b 2f 72 71 2b|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024673; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 3"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"5c29zZXJpYWwv"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024670; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 1"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"eXNvc2VyaWFsL"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024668; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 4"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|79 76 36 36 76|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024671; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin ysoserial Usage (B64) 2"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"lzb3NlcmlhbC"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024669; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag possible_exploitation, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (B64) 5"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"|72 2b 75 72|"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024672; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
suricata·2017-09-07·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin (Runtime.Exec)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/struts2-rest-showcase/orders/3"; http.request_body; content:"java.lang.Runtime"; nocase; fast_pattern; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024674; rev:4; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_07, cve CVE_2017_9805, deployment Datacenter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
suricata·2017-09-06·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (ProcessBuilder)"; flow:established,to_server; http.request_body; content:"java.lang.ProcessBuilder"; nocase; fast_pattern; content:"]/Rs"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024663; rev:3; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_06, cve CVE_2017_9805, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
suricata·2017-09-06·CVSS 8.1
CVE-2017-9805 [HIGH] ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache Struts 2 REST Plugin XStream RCE (Runtime.Exec)"; flow:established,to_server; http.request_body; content:"java.lang.Runtime"; nocase; fast_pattern; content:".exec"; distance:0; content:"]/Rs"; reference:cve,2017-9805; reference:url,lgtm.com/blog/apache_struts_CVE-2017-9805_announcement; classtype:attempted-user; sid:2024664; rev:3; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2017_09_06, cve CVE_2017_9805, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
No public exploits indexed.
No writeups or analysis indexed.
2024-10-10
Published