mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
Add CVE-2016-4437
This commit is contained in:
parent
8fa66ef91d
commit
f9c130ae36
BIN
Shiro/CVE-2016-4437/CVE-2016-4437_1.png
Normal file
BIN
Shiro/CVE-2016-4437/CVE-2016-4437_1.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 134 KiB |
BIN
Shiro/CVE-2016-4437/CVE-2016-4437_2.png
Normal file
BIN
Shiro/CVE-2016-4437/CVE-2016-4437_2.png
Normal file
Binary file not shown.
After Width: | Height: | Size: 141 KiB |
13
Shiro/CVE-2016-4437/README.md
Normal file
13
Shiro/CVE-2016-4437/README.md
Normal file
@ -0,0 +1,13 @@
|
||||
# CVE-2016-4437 Apache Shiro Deserialization Vulnerability
|
||||
|
||||
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
|
||||
|
||||
**Affected Version**: Apache Shiro < 1.2.5
|
||||
|
||||
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJBcGFjaGUtU2hpcm8i) query rule**: app="Apache-Shiro"
|
||||
|
||||
# Demo
|
||||
|
||||

|
||||
|
||||

|
Loading…
x
Reference in New Issue
Block a user