Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2016-6812 PoC — Apache CXF 跨站脚本漏洞

Source
Associated Vulnerability
Title:Apache CXF 跨站脚本漏洞 (CVE-2016-6812)
Description:The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.
Readme
[![Build Status](https://ci-builds.apache.org/job/CXF/job/pipeline/job/main/badge/icon?subject=Build)](https://ci-builds.apache.org/job/CXF/job/pipeline/job/main/)
[![Maven Central](https://maven-badges.herokuapp.com/maven-central/org.apache.cxf/cxf/badge.svg)](https://maven-badges.herokuapp.com/maven-central/org.apache.cxf/cxf)
[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/cxf/badge)](https://api.securityscorecards.dev/projects/github.com/apache/cxf)
[![OpenSSF Best Practices](https://bestpractices.coreinfrastructure.org/projects/6978/badge)](https://bestpractices.coreinfrastructure.org/projects/6978)

Welcome to Apache CXF!
======================
Apache CXF is an open source services framework. CXF helps you build and 
develop services using frontend programming APIs, like JAX-WS and JAX-RS. 
These services can speak a variety of protocols such as SOAP, XML/HTTP, 
RESTful HTTP, or CORBA and work over a variety of transports such as HTTP,
JMS or JBI.

CXF includes a broad feature set, but it is primarily focused on the following 
areas:

- Web Services Standards Support: CXF supports a variety of web service 
  standards including SOAP, the Basic Profile, WSDL, WS-Addressing, 
  WS-Policy, WS-ReliableMessaging, WS-Security, WS-SecurityPolicy,
  WS-SecureConversation, and WS-Trust.
- Frontends: CXF supports a variety of "frontend" programming models. CXF
  implements the JAX-WS APIs. It also includes a "simple frontend" which 
  allows creation of clients and endpoints without annotations. CXF supports 
  both contract first development with WSDL and code first development 
  starting from Java.  There is also a JAX-RS frontend for providing 
  REST support.
- Ease of use: CXF is designed to be intuitive and easy to use. There 
  are simple APIs to quickly build code-first services, Maven plug-ins to 
  make tooling integration easy, JAX-WS API support, Spring 2.x XML support 
  to make configuration a snap, and much more.
- Binary and Legacy Protocol Support: CXF has been designed to provide a 
  pluggable architecture that supports not only XML but also non-XML type 
  bindings, such as JSON and CORBA, in combination with any type of transport.


Export Notice
============================
This distribution includes cryptographic software.  The country in 
which you currently reside may have restrictions on the import, 
possession, use, and/or re-export to another country, of 
encryption software.  BEFORE using any encryption software, please 
check your country's laws, regulations and policies concerning the
import, possession, or use, and re-export of encryption software, to 
see if this is permitted.  See <http://www.wassenaar.org/> for more
information.

The U.S. Government Department of Commerce, Bureau of Industry and
Security (BIS), has classified this software as Export Commodity 
Control Number (ECCN) 5D002.C.1, which includes information security
software using or performing cryptographic functions with asymmetric
algorithms.  The form and manner of this Apache Software Foundation
distribution makes it eligible for export under the License Exception
ENC Technology Software Unrestricted (TSU) exception (see the BIS 
Export Administration Regulations, Section 740.13) for both object 
code and source code.

The following provides more details on the included cryptographic
software:
- http://santuario.apache.org/
- http://www.bouncycastle.org/
- http://ws.apache.org/wss4j/



Getting Started
===============

For an Apache CXF source distribution, please read BUILDING.txt for 
instructions on building Apache CXF. 

For an Apache CXF binary distribution, please read release_notes.txt
for installation instructions and list of supported and unsupported 
features.

Alternatively, you can also find out how to get started here:
http://cxf.apache.org/

If you need more help try talking to us on our mailing lists:
http://cxf.apache.org/mailing-lists.html
 
If you find any issues with CXF, please submit reports with JIRA here:
https://issues.apache.org/jira/browse/CXF

We welcome contributions, and encourage you to get involved in the CXF
community. If you'd like to learn more about how you can contribute, please
see:
http://cxf.apache.org/getting-involved.html

Thank you for using CXF!

The Apache CXF Team
http://cxf.apache.org/
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →