Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
PoC: CVE-2021-26295
CVE-2021-26295 EXP 可成功反弹Shell
PoC: CVE-2021-26295-Apache-OFBiz-EXP
Apache OFBiz rmi反序列化EXP(CVE-2021-26295)
PoC: CVE-2021-26295-Apache-OFBiz
CVE-2021-26295 Apache OFBiz rmi反序列化POC
PoC: CVE-2021-26295--
CVE-2021-26295-POC 利用DNSlog进行CVE-2021-26295的漏洞验证。 使用 poc:将目标放于target.txt后运行python poc.py即可。(Jdk环境需<12,否则ysoserial无法正常生成有效载荷) exp:python exp.py https://baidu.com然后进入命令执行界面(无回显)
PoC: CVE-2021-26295
CVE-2021-26295 EXP 可成功反弹Shell
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free