CVE-2022-34267: RWS WorldServer – Authentication Bypass

CVE-2022-34267: RWS WorldServer - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2022-34267: RWS WorldServer – Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-34267: RWS WorldServer – Authentication Bypass

漏洞描述

An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享