CVE-2019-17570
CRITICALApache XML-RPC - Remote Code Execution via Untrusted Deserialization in XmlRpcResponseParser
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2019-17570. PoCs published by r00t4dm, im23pds, slowmistio.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2019-17570, a deserialization vulnerability in Apache XML-RPC. The exploit sets up a malicious server that crafts a response with a serialized payload to trigger remote code execution on vulnerable clients.
Description
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
Exploits (3)
This repository contains a functional proof-of-concept exploit for CVE-2019-17570, a deserialization vulnerability in Apache XML-RPC. The exploit sets up a malicious server that crafts a response with a serialized payload to trigger remote code execution on vulnerable clients.
This repository contains a functional exploit for CVE-2019-17570, demonstrating a deserialization vulnerability in Apache XML-RPC's `xmlrpc-common` library. The PoC includes a malicious XML-RPC server and a vulnerable client, leveraging a gadget chain from Apache Commons Collections to achieve remote code execution.
This repository contains a functional exploit for CVE-2019-17570, demonstrating a deserialization vulnerability in Apache XML-RPC's `xmlrpc-common` library. The PoC includes a malicious XML-RPC server and a vulnerable client, leveraging a gadget chain from Apache Commons Collections to achieve remote code execution.
References (11)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H