CVE-2020-24589: WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection

CVE-2020-24589: WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2020-24589: WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-24589: WSO2 API Manager <=3.1.0 – Blind XML External Entity Injection

漏洞描述

WSO2 API Manager 3.1.0 and earlier is vulnerable to blind XML external entity injection (xxe). XXE often allows an attacker to view files on the server file system, and to interact with any backend or external systems that the application itself can access which allows the attacker to transmit sensitive data from the compromised server to a system that the attacker controls.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享