CVE-2022-29464: WSO2 Management – Arbitrary File Upload & Remote Code Execution

CVE-2022-29464: WSO2 Management - Arbitrary File Upload & Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2022-29464: WSO2 Management – Arbitrary File Upload & Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-29464: WSO2 Management – Arbitrary File Upload & Remote Code Execution

漏洞描述

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享