Apache Struts2 CVE-2017-5638 OGNL RCE Exploitation Attempt

Detects incoming HTTP traffic attempting to exploit the Apache Struts2 vulnerability CVE-2017-5638. The rule monitors the Content-Type HTTP header for OGNL (Object-Graph Navigation Language) expressions containing known exploitation markers like ClassLoader, getRuntime, or .exec(), which indicate an attempt to achieve Remote Code Execution (RCE).