Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2013-2186

Description

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

POC

Reference

- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html

- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

- https://www.tenable.com/security/research/tra-2016-23

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/AdeliaNitzsche/Java-Deserialization-Cheat-Sheet

- https://github.com/BrittanyKuhn/javascript-tutorial

- https://github.com/CVEDB/PoC-List

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/CrackerCat/myhktools

- https://github.com/GhostTroops/myhktools

- https://github.com/GrrrDog/ACEDcup

- https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet

- https://github.com/JERRY123S/all-poc

- https://github.com/PalindromeLabs/Java-Deserialization-CVEs

- https://github.com/SPlayer1248/CVE_2013_2186

- https://github.com/SPlayer1248/Payload_CVE_2013_2186

- https://github.com/adedov/victims-version-search

- https://github.com/alexsh88/victims

- https://github.com/bqcuong/vul4j

- https://github.com/cyberanand1337x/bug-bounty-2022

- https://github.com/do0dl3/myhktools

- https://github.com/hktalent/TOP

- https://github.com/hktalent/myhktools

- https://github.com/iqrok/myhktools

- https://github.com/jbmihoub/all-poc

- https://github.com/klausware/Java-Deserialization-Cheat-Sheet

- https://github.com/klee94/maven-security-versions-Travis

- https://github.com/mishmashclone/GrrrDog-Java-Deserialization-Cheat-Sheet

- https://github.com/sa1g0n1337/CVE_2013_2186

- https://github.com/sa1g0n1337/Payload_CVE_2013_2186

- https://github.com/speedyfriend67/Experiments

- https://github.com/tmpgit3000/victims

- https://github.com/touchmycrazyredhat/myhktools

- https://github.com/tranphuc2005/Privilege-Escalation-Linux-with-JBoss

- https://github.com/tranphuc2005/leoquyen_linux

- https://github.com/trhacknon/myhktools

- https://github.com/tuhh-softsec/vul4j

- https://github.com/victims/maven-security-versions

- https://github.com/weeka10/-hktalent-TOP

- https://github.com/zema1/oracle-vuln-crawler