
प्री-ऑथेंटिकेशन रिमोट कोड एक्ज़ीक्यूशन प्रूफ-ऑफ-कॉन्सेप्ट Apache OFBiz CVE-2023-49070 के लिए, जो XML-RPC Java deserialization का शोषण कर ysoserial पेलोड वितरित करता है।
यह CVE-2023-49070 के लिए एक प्री-ऑथ RCE POC है, जो Apache ofbiz एप्लिकेशन < 18.12.10 को xml-rpc जावा डिसीरियलाइजेशन बग के कारण प्रभावित करता है।
अधिक जानकारी के लिए कृपया देखें: https://github.com/advisories/GHSA-9rm6-p86c-42xm
डॉकराइज़्ड संवेदनशील ofbiz इमेज: https://hub.docker.com/r/marcopinball/ofbiz-demo
wget https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar


यह एक्सप्लॉइट Abdelhameed Ghazy द्वारा विकसित किया गया है।
ट्विटर: https://twitter.com/abd0ghazy
लिंक्डइन: https://www.linkedin.com/in/abdelhameed-ghazy-1a50b619a/