
Exploit de preuve de concept pour CVE-2020-9496 (Apache OFBiz) avec intégration de templates nuclei et mise en place pas à pas d'un environnement vulnérable pour les tests de sécurité et la formation.
▶ wget http://archive.apache.org/dist/ofbiz/apache-ofbiz-17.12.01.zip
▶ unzip apache-ofbiz-17.12.01.zip
▶ cd apache-ofbiz-17.12.01
▶ sh gradle/init-gradle-wrapper.sh
▶ ./gradlew cleanAll loadDefault
▶ ./gradlew "ofbiz --load-data readers=seed,seed-initial,ext"
▶ ./gradlew ofbiz # Start OFBiz
Ouvrez un navigateur et allez sur https://localhost:8443.
Le compte administrateur par défaut est nom d'utilisateur : admin mot de passe : ofbiz.
> echo "https://localhost:8443" | nuclei -t cves/CVE-2020-9496.yaml