CVE-2021-29156: LDAP Injection In OpenAM

CVE-2021-29156: LDAP Injection In OpenAM-渗透云记 - 专注于网络安全与技术分享
CVE-2021-29156: LDAP Injection In OpenAM
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-29156: LDAP Injection In OpenAM

漏洞描述

OpenAM contains an LDAP injection vulnerability. When a user tries to reset his password, they are asked to enter username, and then the backend validates whether the user exists or not through an LDAP query. If the user exists, the password reset token is sent to the user's email. Enumeration can allow for full password retrieval.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享