This is a serious exploit on Apache Struts 2, a popular Java Web framework known as SSH (Spring, Struts, Hibernate). If you visit many websites, and see URLs ending with .action , it's probably written in Struts 2
S2-016 / CVE-2013-2251, effecting Struts 2.3.15 or lower
http://struts.apache.org/release/2.3.x/docs/s2-016.html
The exploit was deadly easy to weaponize as the Apache folks blatantly published PoC on their own bulletin
Example of server side arbitary Java code (OGNL expressions) execution
http://wp3.sina.cn/woriginal/761d2801jw1e6pqfs8hrbj20c70gomy...
Apple.com hacking was published on a popular Chinese security bulletin website
http://www.wooyun.org/bugs/wooyun-2013-023444
The issue was submitted to APPL on 2013-05-10 but ignored, and went public on 2013-06-24.
A Chinese blog on history and technical details of the exploit:
http://www.inbreak.net/archives/507
As a side note, rumor is that about 60% of Chinese goverment, e-commerce, banking, gaming websites was hacked using this S2-016 exploit, database was dumped, and exchanged in underground market. Also past records shows that the Apache Struts team is incompetent at security:
http://taosay.net/?p=611 (Warning: rant in Chinese text)