mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-05-06 10:41:40 +00:00
Add Geowebserver 5.3.3 Arbitrary File Read
This commit is contained in:
parent
8a4091a8b8
commit
8aa199011a
9
Geowebserver/5_3_3_Arbitrary_File_Read/README.md
Normal file
9
Geowebserver/5_3_3_Arbitrary_File_Read/README.md
Normal file
@ -0,0 +1,9 @@
|
||||
# Geowebserver 5.3.3 Arbitrary File Read
|
||||
|
||||
GEOVISION GEOWEBSERVER less than 5.3.3 are vulnerable to several XSS ,HTML Injection ,Local File Include ,XML Injection ,Code execution vectors. The application fails to properly sanitize user requests. This allows injection of HTML code and XSS ,client side exploitation, including session theft.
|
||||
|
||||
FOFA **query rule**: [app="Geowebserver"](https://fofa.so/result?qbase64=YXBwPSJHZW93ZWJzZXJ2ZXIi)
|
||||
|
||||
# Demo
|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user