andresriancho / w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.
http://w3af.org/
4.57k stars 1.22k forks source link

RCE via Spring Engine SSTI #16327

Open andresriancho opened 6 years ago

andresriancho commented 6 years ago

It would be nice to have a plugin which tests for this vulnerability!

https://hawkinsecurity.com/2017/12/13/rce-via-spring-engine-ssti/

amitsin6h commented 6 years ago

@andresriancho can I take this issue as my first contribution

andresriancho commented 6 years ago

Sure! How can I help you succeed with the development of this new plugin?