Exploitation Summary
EIP tracks 2 public exploits for CVE-2016-0710.
PoCs published by Metasploit, Andreas Lindh, wvu, including Metasploit module exploits/multi/http/apache_jetspeed_file_upload.
AI-analyzed exploit summary This Metasploit module exploits CVE-2016-0710 in Apache Jetspeed by leveraging an unsecured REST API to create an admin user and a ZIP path traversal vulnerability to upload and execute a JSP shell.
Description
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
Exploits (2)
This Metasploit module exploits CVE-2016-0710 in Apache Jetspeed by leveraging an unsecured REST API to create an admin user and a ZIP path traversal vulnerability to upload and execute a JSP shell.
This Metasploit module exploits CVE-2016-0710 in Apache Jetspeed by leveraging an unsecured User Manager REST API and a ZIP file path traversal to upload and execute a JSP shell. It creates an admin user, logs in, uploads a malicious ZIP file, and triggers the payload.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H