CVE-2024-36401: GeoServer RCE in Evaluating Property Name Expressions

CVE-2024-36401: GeoServer RCE in Evaluating Property Name Expressions-渗透云记 - 专注于网络安全与技术分享
CVE-2024-36401: GeoServer RCE in Evaluating Property Name Expressions
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-36401: GeoServer rce in Evaluating Property Name Expressions

漏洞描述

In the GeoServer version prior to 2.25.1, 2.24.3 and 2.23.5 of GeoServer, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享