rce via java deserialization
parent
211ddcc575
commit
41f25f0fc2
|
@ -0,0 +1,18 @@
|
|||
info:
|
||||
name: Java Deserialization [RCE]
|
||||
author: uhnysh
|
||||
severity: critical
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- "{{BaseURL}}/josso/%5C../invoker/EJBInvokerServlet/"
|
||||
- "{{BaseURL}}/josso/%5C../invoker/JMXInvokerServlet/"
|
||||
- "{{BaseURL}}/invoker/JMXInvokerServlet/"
|
||||
- "{{BaseURL}}/invoker/EJBInvokerServlet/"
|
||||
matchers:
|
||||
- type: word
|
||||
words:
|
||||
- "org.jboss.invocation.MarshalledValue"
|
||||
- "java.lang"
|
||||
condition: or
|
Loading…
Reference in New Issue