CVE-2020-9496
MEDIUM EXPLOITED IN THE WILD NUCLEIApache OFBiz 17.12.03 - Deserialization of Untrusted Data and Cross-Site Scripting via XML-RPC Requests
Title source: llmExploitation Summary
CVE-2020-9496 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 10 public exploits from researchers including Adrián Díaz, g33xter, yuaneuro. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages unsafe deserialization in Apache OfBiz 17.12.01 via XMLRPC endpoints to achieve remote command execution. It uses ysoserial to generate malicious payloads and delivers them through crafted XMLRPC requests.
Description
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Exploits (10)
This exploit leverages unsafe deserialization in Apache OfBiz 17.12.01 via XMLRPC endpoints to achieve remote command execution. It uses ysoserial to generate malicious payloads and delivers them through crafted XMLRPC requests.
This repository provides a functional exploit for CVE-2020-9496, leveraging unsafe Java deserialization in Apache OFBiz's xmlrpc endpoint to achieve remote code execution (RCE). The PoC uses ysoserial to generate a malicious payload and delivers it via a crafted XMLRPC request.
This repository contains functional exploit code for CVE-2021-26295, a deserialization vulnerability in Apache OFBiz. The PoC leverages ysoserial to generate malicious payloads and uses DNS logging for verification, demonstrating remote code execution capabilities.
This repository contains a functional exploit for CVE-2020-9496, an unsafe deserialization vulnerability in Apache OFBiz. The exploit leverages the ysoserial tool to generate malicious payloads and sends them to the vulnerable XML-RPC endpoint, resulting in remote code execution.
The repository provides setup instructions for a vulnerable Apache OFBiz environment and references a Nuclei template for detecting CVE-2020-9496, which is a deserialization vulnerability. It does not include direct exploit code but leverages an external scanner.
This repository contains a functional exploit for CVE-2020-9496, targeting Apache OFBiz 17.12.01 via unsafe deserialization in XML-RPC requests. The exploit automates the delivery of a reverse shell payload using ysoserial and curl commands.
The repository contains only a README with a YouTube link and no actual exploit code or technical details about CVE-2020-9496. This is indicative of a social engineering lure rather than a legitimate PoC.
This repository contains a functional exploit for CVE-2020-9496, which targets an unsafe deserialization vulnerability in Apache OFBiz 17.12.03. The exploit uses ysoserial to generate a malicious payload and sends it via an XML-RPC request to achieve remote code execution.
This repository contains a functional exploit for CVE-2020-9496, which leverages unsafe deserialization in Apache OFBiz 17.12.03 via XML-RPC requests. The exploit uses ysoserial to generate a malicious payload and sends it to the target endpoint to achieve remote code execution.
This repository provides a functional exploit for CVE-2020-9496, an unsafe deserialization vulnerability in Apache OFBiz. The exploit leverages ysoserial to generate a malicious payload, which is then sent via a crafted XMLRPC request to achieve remote code execution (RCE).
Nuclei Templates (1)
http.html:"ofbiz" || ofbiz.visitor=
body="ofbiz" || app="apache_ofbiz"
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N