Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-41474. PoCs published by JBalanza.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-41474, an unauthenticated path traversal vulnerability in Ivanti Avalanche Server v6.3.4.153. It includes exploitation steps, impact assessment, and a method to escalate the attack by dumping heap memory to extract credentials.
Description
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2023-41474, an unauthenticated path traversal vulnerability in Ivanti Avalanche Server v6.3.4.153. It includes exploitation steps, impact assessment, and a method to escalate the attack by dumping heap memory to extract credentials.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N