Lucene search

K
githubexploit27621ADE-268E-5783-BCC7-820152859645
HistoryDec 29, 2023 - 2:25 a.m.

Exploit for Server-Side Request Forgery in Apache Ofbiz

2023-12-2902:25:43
331
server-side request forgery
apache ofbiz
cve-2023-51467
serialization vulnerability
authentication bypass
command execution
groovy filtering bypass

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.639 Medium

EPSS

Percentile

97.9%

CVE-2023-51467

exp.py 改为命令执行

Post.txt

序列化漏洞利用

bypassa…

This is an article that belongs to githubexploit private collection.
Please sign in to get more Information.

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.639 Medium

EPSS

Percentile

97.9%