mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
1008 B
1008 B
CVE-2020-24379
Description
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
POC
Reference
- https://github.com/vulnbe/poc-yaws-dav-xxe
- https://github.com/vulnbe/poc-yaws-dav-xxe
- https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
- https://packetstormsecurity.com/files/159106/Yaws-2.0.7-XML-Injection-Command-Injection.html
- https://vuln.be/post/yaws-xxe-and-shell-injections/
- https://vuln.be/post/yaws-xxe-and-shell-injections/