Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-11975 PoC — Apache Unomi 输入验证错误漏洞

Source
Associated Vulnerability
Title:Apache Unomi 输入验证错误漏洞 (CVE-2020-11975)
Description:Apache Unomi是美国阿帕奇软件(Apache Software)基金会的一套开源的客户数据平台。该平台主要使用Java语言编写。 Apache Unomi 1.5.1之前版本中存在安全漏洞。攻击者可利用该漏洞执行代码。
Description
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process, enabling attackers to execute arbitrary code.
File Snapshot

id: CVE-2020-11975 info: name: Apache Unomi - Remote Code Execution author: Sourabh-Sahu seve ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.