Record summary

CVE-2019-17570 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs.

Description

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
2

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListApache XML-RPC all versionsaffected
GitHub AdvisoryThrough 3.1.3affected

Proofs of concept

2

Repository PoCs

GitHubr00t4dm/CVE-2019-17570Repository PoCby r00t4dmStars: 4Not analyzed19 files

27.3 KiB

GitHub

PoC details
GitHubim23pds/xmlrpc-common-deserializationRepository PoCby im23pdsStars: 0Not analyzed6 files

19.1 KiB

GitHub

PoC details

References

Showing 12 of 14