Swagger 通过参数注入远程代码执行漏洞

Basic Fields

SSV ID:
SSV-91951
Find Time:
Unknown
Submit Time:
2016-06-27
Level:
Category:
代码执行
Component:
Swagger
Author:
Scott Davis of Rapid7,
Submitter:
Knownsec
CVE-ID:
CVE-2016-5641
CNNVD-ID:
Add
CNVD-ID:
Add
ZoomEye Dork:
Add

Source

Detail

Contributor Knownsec Got  0KB
Loading icon
have 0  exchange

PoC (非 pocsuite 插件)

Contributor Knownsec totally have   1.85KB

whoam1 blackstar XiaoXu etc 11 Exchange

Reference Linking

Solutions

Temp Solutions

Unavailable Temp Solutions

Official Solution

Unavailable Official solution

Defense Solutions

Unavailable Defense Solutions

Popularity 16038
Need to bind phone before comment. Bind Now

All Comments (1)

  • haohaode
    寻求入侵指定网站 获取网站数据技术合作 接受测试的加下我 我的QQ564121595 成功合作将有高额报酬 保证月薪六位数以上
    1F

※Any content provided by this site, only to learn the code and services, not for illegal purposes