Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-34267 PoC — RWS WorldServer 安全漏洞

Source
Associated Vulnerability
Title:RWS WorldServer 安全漏洞 (CVE-2022-34267)
Description:RWS WorldServer是英国RWS公司的一个灵活的企业级翻译管理系统。 RWS WorldServer 11.7.3之前版本存在安全漏洞,该漏洞源于会绕过所有身份验证要求,攻击者利用该漏洞可以执行任意Java代码。
Description
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.
File Snapshot

id: CVE-2022-34267 info: name: RWS WorldServer - Authentication Bypass author: pdresearch,iamno ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.