CVE-2017-1000028
HIGH EXPLOITED NUCLEIOracle GlassFish Server Open Source Edition 4.1 - Path Traversal
Title source: llmExploitation Summary
CVE-2017-1000028 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 5 public exploits from researchers including Metasploit, Trustwave's SpiderLabs, Dhiraj Mishra, including a Metasploit module auxiliary/scanner/http/glassfish_traversal.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated directory traversal vulnerability in Oracle GlassFish Server 4.1 by sending a crafted HTTP GET request to read arbitrary files. The exploit uses a traversal string with encoded characters to bypass path restrictions.
Description
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
Exploits (5)
This Metasploit module exploits an unauthenticated directory traversal vulnerability in Oracle GlassFish Server 4.1 by sending a crafted HTTP GET request to read arbitrary files. The exploit uses a traversal string with encoded characters to bypass path restrictions.
This exploit demonstrates a path traversal vulnerability in Oracle GlassFish Server Open Source Edition 4.1 and prior. It uses URL-encoded directory traversal sequences (%c0%af..) to access sensitive files like win.ini and /etc/shadow.
This Metasploit module exploits an unauthenticated path traversal vulnerability in Oracle GlassFish Server 4.1 via a crafted URI to read arbitrary files. It uses a double-encoded traversal sequence to bypass security checks.
This repository contains a functional Python exploit for CVE-2017-1000028, a directory traversal vulnerability in GlassFish versions prior to 4.1.1. The exploit leverages a path traversal technique using URL-encoded characters to read arbitrary files, such as /etc/passwd, from the target system.
This Metasploit module exploits an unauthenticated directory traversal vulnerability in Oracle GlassFish Server 4.1 via a crafted HTTP GET request to the administration console. It reads arbitrary files by leveraging a path traversal technique with encoded characters.
Nuclei Templates (1)
cpe:"cpe:2.3:a:oracle:glassfish_server"
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N