mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-12-31 23:12:20 +00:00
add CVE-2020-9496
This commit is contained in:
parent
e95280978e
commit
c98d280949
BIN
OFBiz/CVE-2020-9496/CVE-2020-9496.gif
Normal file
BIN
OFBiz/CVE-2020-9496/CVE-2020-9496.gif
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 207 KiB |
11
OFBiz/CVE-2020-9496/README.md
Normal file
11
OFBiz/CVE-2020-9496/README.md
Normal file
@ -0,0 +1,11 @@
|
||||
# CVE-2020-9496 Apache OFBiz Deserialization RCE
|
||||
|
||||
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
|
||||
|
||||
**Affected version**: Apache OFBiz 17.12.03
|
||||
|
||||
**[FOFA](https://fofa.so/result?q=header%3D%22Set-Cookie%3A+OFBiz.Visitor%22&qbase64=aGVhZGVyPSJTZXQtQ29va2llOiBPRkJpei5WaXNpdG9yIg%3D%3D&file=&file=) query rule**: header="Set-Cookie: OFBiz.Visitor"
|
||||
|
||||
# Demo
|
||||
|
||||

|
||||
Loading…
x
Reference in New Issue
Block a user