CVE-2017-5645: Apache Log4j Server – Deserialization Command Execution

CVE-2017-5645: Apache Log4j Server - Deserialization Command Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2017-5645: Apache Log4j Server – Deserialization Command Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2017-5645: Apache Log4j Server – Deserialization Command Execution

漏洞描述

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享