Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-24589 PoC — WSO2 API Manager 安全漏洞

Source
Associated Vulnerability
Title:WSO2 API Manager 安全漏洞 (CVE-2020-24589)
Description:WSO2 API Manager是美国WSO2公司的一套API生命周期管理解决方案。 WSO2 API Manager中存在漏洞。以下产品及版本受到影响:WSO2 API Manager从3.1.0 开始版本和 API Microgateway 2.2.0版本。
Description
WSO2 API Manager 3.1.0 and earlier is vulnerable to blind XML external entity injection (XXE). XXE often allows an attacker to view files on the server file system, and to interact with any backend or external systems that the application itself can access which allows the attacker to transmit sensitive data from the compromised server to a system that the attacker controls.
File Snapshot

id: CVE-2020-24589 info: name: WSO2 API Manager <=3.1.0 - Blind XML External Entity Injection a ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.