S2-032: Remote Code Execution Vulnerability (CVE-2016-3081)
This document details the Apache Struts2 S2-032 remote code execution vulnerability, affecting versions 2.3.20 to 2.3.28 (excluding specific patches). It occurs when Dynamic Method Invocation is enabled, allowing the `method:<name>` syntax to evaluate OGNL expressions. The vulnerability can be exploited by sending a crafted URL to execute arbitrary commands like `id`. The document provides links for further details and instructions to set up a vulnerable environment using Struts2 2.3.28.