跳转到帖子

Jorani unauthenticated Remote Code Execution

recommended_posts

发布于
  • Members

Jorani unauthenticated Remote Code Execution

Disclosed
01/06/2023
Created
08/19/2023

Description

This module exploits an unauthenticated Remote Code Execution in Jorani prior to 1.0.2. It abuses 3 vulnerabilities: log poisoning and redirection bypass via header spoofing, then it uses path traversal to trigger the vulnerability. It has been tested on Jorani 1.0.0.

Author(s)

  • RIOUX Guilhem (jrjgjk)

Platform

PHP

Architectures

php

Development

  • Source Code
  • History
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…