mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
add CVE-2020-13942
This commit is contained in:
parent
b23ae4f252
commit
4253125256
BIN
Unomi/CVE-2020-13942/CVE-2020-13942.gif
Normal file
BIN
Unomi/CVE-2020-13942/CVE-2020-13942.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 569 KiB |
11
Unomi/CVE-2020-13942/README.md
Normal file
11
Unomi/CVE-2020-13942/README.md
Normal file
@ -0,0 +1,11 @@
|
||||
# CVE-2020-13942 Apache Unomi RCE
|
||||
|
||||
Apache Unomi allows conditions to use OGNL and MVEL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
|
||||
|
||||
**Affected version**: Apache Unomi <= 1.5.1
|
||||
|
||||
**[FOFA](https://fofa.so/result?q=title%3D%22Apache+Unomi+Welcome+Page%22&qbase64=dGl0bGU9IkFwYWNoZSBVbm9taSBXZWxjb21lIFBhZ2Ui&file=&file=) query rule**: title="Apache Unomi Welcome Page"
|
||||
|
||||
# Demo
|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user