CVE-2016-4977: Spring Security OAuth2 Remote Command Execution

CVE-2016-4977: Spring Security OAuth2 Remote Command Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2016-4977: Spring Security OAuth2 Remote Command Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2016-4977: SpRing Security OAuth2 Remote Command Execution

漏洞描述

Spring Security OAuth versions 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5 contain a remote command execution vulnerability. When processing authorization requests using the whitelabel views, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote command execution via the crafting of the value for response_type.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享