CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 - Manager Access

CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 - Manager Access-渗透云记 - 专注于网络安全与技术分享
CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 - Manager Access
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2018-11759: Apache Tomcat JK Connect <=1.2.44 – Manager Access

漏洞描述

Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 allows specially constructed requests to expose application functionality through the reverse proxy. It is also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享