OGNL (Object-Graph Navigation Language) is the expression language Struts2 uses to move values between the request, the value stack, and the view. Tag attributes, type conversion, and parameter names are all evaluated as OGNL, written %{...} in tags and reachable as ${...} in some contexts. When request data flows into a string that Struts then evaluates, through a forced double evaluation, a crafted parameter name, or a tag attribute built from input, the OGNL grammar runs against the value stack.
OGNL is a full object language: it names classes, constructs objects, and calls methods. Modern Struts2 wraps evaluation in a sandbox, a SecurityMemberAccess with excluded classes and package names enforced through the OGNL context, so a bare java.lang.Runtime call is blocked. The exploitation pages below cover both proving evaluation without touching the sandbox and clearing the member-access restriction to reach the runtime.
- Directory listing: the blind arithmetic and string-evaluation probe that confirms OGNL evaluation before any runtime call.
- Remote code execution: restoring member access and reaching
RuntimeandProcessBuilder. - Remote file inclusion: constructing
java.io.Fileandjava.net.URLto read local files and fetch remote content.