Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-5830 PoC — ColumbiaSoft Document Locator 安全漏洞

Source
Associated Vulnerability
Title:ColumbiaSoft Document Locator 安全漏洞 (CVE-2023-5830)
Description:ColumbiaSoft Document Locator是ColumbiaSoft公司的一个文档管理系统。 ColumbiaSoft Document Locator 7.2 SP4之前版本存在安全漏洞,该漏洞源于文件/api/authentication/login的参数Server会导致不正确的身份验证。
Description
Instances of ColumbiaSoft's Document Locator prior to version 7.2 SP4 and 2021.1 are vulnerable to an Improper Authentication/SSRF vulnerability. This template identifies vulnerable instances of the ColumbiaSoft Document Locater application by confirming external DNS interaction/lookups by modifying the value of the client-side SERVER parameter at /api/authentication/login.
File Snapshot

id: CVE-2023-5830 info: name: ColumbiaSoft DocumentLocator - Improper Authentication author: Go ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.