Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-7961

Description

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

POC

Reference

- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.html

- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Execution.html

Github

- https://github.com/0x4ymn/PENTESTING_BIBLE

- https://github.com/0x7n6/BIBLE

- https://github.com/0xT11/CVE-POC

- https://github.com/0xZipp0/BIBLE

- https://github.com/20142995/Goby

- https://github.com/20142995/nuclei-templates

- https://github.com/20142995/pocsuite3

- https://github.com/20142995/sectool

- https://github.com/2lambda123/CVE-mitre

- https://github.com/2lambda123/Windows10Exploits

- https://github.com/3th1c4l-t0n1/awesome-csirt

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ARPSyndicate/kenzer-templates

- https://github.com/Ashadowkhan/PENTESTINGBIBLE

- https://github.com/Astrogeorgeonethree/Starred

- https://github.com/Astrogeorgeonethree/Starred2

- https://github.com/Atem1988/Starred

- https://github.com/Coldplay1517/Middleware-Vulnerability-detection-master

- https://github.com/Correia-jpv/fucking-awesome-web-security

- https://github.com/CrackerCat/CVE-2020-7961-Mass

- https://github.com/Elsfa7-110/kenzer-templates

- https://github.com/HimmelAward/Goby_POC

- https://github.com/Mathankumar2701/ALL-PENTESTING-BIBLE

- https://github.com/MedoX71T/PENTESTING-BIBLE

- https://github.com/Mehedi-Babu/web_security_cyber

- https://github.com/MelanyRoob/Goby

- https://github.com/Merc98/black-hat

- https://github.com/Micle5858/PENTESTING-BIBLE

- https://github.com/NetW0rK1le3r/PENTESTING-BIBLE

- https://github.com/NyxAzrael/Goby_POC

- https://github.com/OCEANOFANYTHING/PENTESTING-BIBLE

- https://github.com/Offensive-Penetration-Security/OPSEC-Hall-of-fame

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/Oxc4ndl3/Web-Pentest

- https://github.com/PalindromeLabs/Java-Deserialization-CVEs

- https://github.com/PuddinCat/GithubRepoSpider

- https://github.com/Rayyan-appsec/ALL-PENTESTING-BIBLE

- https://github.com/Saidul-M-Khan/PENTESTING-BIBLE

- https://github.com/SexyBeast233/SecBooks

- https://github.com/ShutdownRepo/CVE-2020-7961

- https://github.com/Spacial/awesome-csirt

- https://github.com/ThePirateWhoSmellsOfSunflowers/TheHackerLinks

- https://github.com/Threekiii/Awesome-Exploit

- https://github.com/Threekiii/Awesome-POC

- https://github.com/Threekiii/Vulhub-Reproduce

- https://github.com/Udyz/CVE-2020-7961-Mass

- https://github.com/XiaomingX/awesome-poc-for-red-team

- https://github.com/Z0fhack/Goby_POC

- https://github.com/apachecn-archive/Middleware-Vulnerability-detection

- https://github.com/aw-junaid/Web-Security

- https://github.com/bakery312/Vulhub-Reproduce

- https://github.com/bjknbrrr/PENTESTING-BIBLE

- https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE

- https://github.com/codereveryday/Programming-Hacking-Resources

- https://github.com/cwannett/Docs-resources

- https://github.com/d4n-sec/d4n-sec.github.io

- https://github.com/developer3000S/PoC-in-GitHub

- https://github.com/dli408097/WebSecurity

- https://github.com/dli408097/pentesting-bible

- https://github.com/ducducuc111/Awesome-web-security

- https://github.com/elinakrmova/awesome-web-security

- https://github.com/erSubhashThapa/pentest-bible

- https://github.com/fofapro/vulfocus

- https://github.com/gacontuyenchien1/Security

- https://github.com/getdrive/PoC

- https://github.com/gobysec/Goby

- https://github.com/guzzisec/PENTESTING-BIBLE

- https://github.com/hacker-insider/Hacking

- https://github.com/hectorgie/PoC-in-GitHub

- https://github.com/iamrajivd/pentest

- https://github.com/imNani4/PENTESTING-BIBLE

- https://github.com/killvxk/Awesome-Exploit

- https://github.com/kpast0/EH-PENTEST-EeBOOK

- https://github.com/lnick2023/nicenice

- https://github.com/lovechinacoco/https-github.com-mai-lang-chai-Middleware-Vulnerability-detection

- https://github.com/manrop2702/CVE-2020-7961

- https://github.com/mathiznogoud/Liferay-Deserialize-POC

- https://github.com/mathiznogoud/Liferay-RCE

- https://github.com/merlinepedra/nuclei-templates

- https://github.com/merlinepedra25/nuclei-templates

- https://github.com/mishmashclone/qazbnm456-awesome-web-security

- https://github.com/mynameiskaleb/Coder-Everyday-Resource-Pack-

- https://github.com/mzer0one/CVE-2020-7961-POC

- https://github.com/neonoatmeal/Coder-Everyday-Resource-Pack-

- https://github.com/neverhavenamee/CVE-2020-7961

- https://github.com/nitishbadole/PENTESTING-BIBLE

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/nu11secur1ty/CVE-mitre

- https://github.com/nu11secur1ty/CVE-nu11secur1ty

- https://github.com/nu11secur1ty/Windows10Exploits

- https://github.com/papa-anniekey/CustomSignatures

- https://github.com/pashayogi/CVE-2020-7961-Mass

- https://github.com/paulveillard/cybersecurity-web-security

- https://github.com/phant0n/PENTESTING-BIBLE

- https://github.com/qazbnm456/awesome-cve-poc

- https://github.com/qazbnm456/awesome-web-security

- https://github.com/random-robbie/liferay-pwn

- https://github.com/raystyle/paper

- https://github.com/readloud/Pentesting-Bible

- https://github.com/retr0-13/Goby

- https://github.com/shacojx/GLiferay-CVE-2020-7961-golang

- https://github.com/shacojx/LifeRCEJsonWSTool-POC-CVE-2020-7961-Gui

- https://github.com/shacojx/POC-CVE-2020-7961-Token-iterate

- https://github.com/sobinge/nuclei-templates

- https://github.com/soosmile/POC

- https://github.com/t31m0/PENTESTING-BIBLE

- https://github.com/tdtc7/qps

- https://github.com/teamdArk5/Sword

- https://github.com/thelostworldFree/CVE-2020-7961-payloads

- https://github.com/tomikoski/common-lists

- https://github.com/tranphuc2005/1day

- https://github.com/tranphuc2005/1day_vulnerability

- https://github.com/whoami-chmod777/Pentesting-Bible

- https://github.com/xbl3/awesome-cve-poc_qazbnm456

- https://github.com/yamori/pm2_logs

- https://github.com/yusufazizmustofa/BIBLE