Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-6801 PoC — Apache Jackrabbit Jackrabbit-Webdav 跨站请求伪造漏洞

Source
Associated Vulnerability
Title:Apache Jackrabbit Jackrabbit-Webdav 跨站请求伪造漏洞 (CVE-2016-6801)
Description:Apache Jackrabbit是美国阿帕奇(Apache)软件基金会的一个完全遵守Java API版的内容存储规范(JCR)的实现。 Apache Jackrabbit中的Jackrabbit-Webdav中的CSRF内容类型检查功能存在跨站请求伪造漏洞。远程攻击者可通过发送包含缺少或特制的Content-Type头的HTTP POST请求利用该漏洞创建资源。以下版本受到影响:Apache Jackrabbit 2.4.6之前的2.4.x版本,2.6.6之前的2.6.x版本,2.8.3之前的2.8.x
Description
Cross-site request forgery (CSRF) 
File Snapshot

[4.0K] /data/pocs/c7f6ae79cac5593430e45d829aa2234f864cbce0 0 directories, 0 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.