Okay so i just woke up and have seen that there is a new 0 day exploit. This exploit affects apache struts 2. Using burp or the python code below...
Separate names with a comma.