Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-42852 PoC — Micro Focus AcuToWeb 安全漏洞

Source
Associated Vulnerability
Title:Micro Focus AcuToWeb 安全漏洞 (CVE-2024-42852)
Description:Micro Focus AcuToWeb是英国Micro Focus公司的一套ACUCOBOL应用程序的Web和移动部署解决方案。 Micro Focus AcuToWeb v.10.5.0.7577C8b版本存在安全漏洞,该漏洞源于容易受到反射型跨站脚本攻击,允许远程攻击者通过index.php组件执行任意代码。
Description
AcuToWeb server/10.5.0.7577c8b is vulnerable to reflected cross-site scripting (XSS) via the portgw parameter. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution.
File Snapshot

id: CVE-2024-42852 info: name: AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting author: ri ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.