CVE-2018-20580
HIGHSmartBear ReadyAPI 2.5.0-2.6.0 - Remote Code Execution via WSDL Import
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-20580. PoCs published by Gilson Camelo, gscamelo.
AI-analyzed exploit summary This exploit leverages a WSDL file with a malicious default parameter value to achieve remote code execution in ReadyAPI. The payload is embedded in the SOAP address location, triggering execution when the victim sends a request.
Description
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
Exploits (2)
This exploit leverages a WSDL file with a malicious default parameter value to achieve remote code execution in ReadyAPI. The payload is embedded in the SOAP address location, triggering execution when the victim sends a request.
This repository provides a detailed writeup and proof-of-concept for CVE-2018-20580, a remote code execution vulnerability in ReadyAPI 2.5.0/2.6.0. The exploit leverages malicious WSDL files to execute arbitrary code on the victim's machine when loaded into ReadyAPI.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H