Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-49070

Description

Pre-auth RCE in Apache Ofbiz 18.12.09.It's due to XML-RPC no longer maintained still present.This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10

POC

Reference

- http://packetstormsecurity.com/files/176323/Apache-OFBiz-18.12.09-Remote-Code-Execution.html

- https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467

Github

- https://github.com/0day404/HV-2024-POC

- https://github.com/0xrobiul/CVE-2023-49070

- https://github.com/0xsyr0/OSCP

- https://github.com/12442RF/POC

- https://github.com/2ptr/BadBizness-CVE-2023-51467

- https://github.com/AMatheusFeitosaM/OSCP-Cheat

- https://github.com/AboSteam/POPC

- https://github.com/Chocapikk/CVE-2023-51467

- https://github.com/D0g3-8Bit/OFBiz-Attack

- https://github.com/DMW11525708/wiki

- https://github.com/EnriqueSanchezdelVillar/NotesHck

- https://github.com/Faizan-Khanx/OSCP

- https://github.com/Jake123otte1/BadBizness-CVE-2023-51467

- https://github.com/Lern0n/Lernon-POC

- https://github.com/Linxloop/fork_POC

- https://github.com/Marco-zcl/POC

- https://github.com/Ostorlab/KEV

- https://github.com/Praison001/Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

- https://github.com/ReflectedThanatos/OSCP-cheatsheet

- https://github.com/Rishi-45/Bizness-Machine-htb

- https://github.com/SantoriuHen/NotesHck

- https://github.com/SenukDias/OSCP_cheat

- https://github.com/SrcVme50/Bizness

- https://github.com/Threekiii/Awesome-POC

- https://github.com/Threekiii/CVE

- https://github.com/Threekiii/Vulhub-Reproduce

- https://github.com/UserConnecting/Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz

- https://github.com/VishuGahlyan/OSCP

- https://github.com/VulnExpo/ExploitHunter

- https://github.com/VulnExpo/nuclei-templates

- https://github.com/Warren-Jace/poc-doc

- https://github.com/WhosGa/MyWiki

- https://github.com/XiaomingX/awesome-poc-for-red-team

- https://github.com/Y4tacker/JavaSec

- https://github.com/Yuan08o/pocs

- https://github.com/abdoghazy2015/ofbiz-CVE-2023-49070-RCE-POC

- https://github.com/admin772/POC

- https://github.com/adminlove520/pocWiki

- https://github.com/adysec/POC

- https://github.com/bakery312/Vulhub-Reproduce

- https://github.com/bruce120/Apache-OFBiz-Authentication-Bypass

- https://github.com/cisp-pte/POC-20241008-sec-fork

- https://github.com/d4n-sec/d4n-sec.github.io

- https://github.com/eeeeeeeeee-code/POC

- https://github.com/exfilt/CheatSheet

- https://github.com/fazilbaig1/oscp

- https://github.com/greenberglinken/2023hvv_1

- https://github.com/iemotion/POC

- https://github.com/ismailmazumder/SL7CVELabsBuilder

- https://github.com/jakabakos/Apache-OFBiz-Authentication-Bypass

- https://github.com/jakeotte/BadBizness-CVE-2023-51467

- https://github.com/jitmondal1/OSCP

- https://github.com/laoa1573/wy876

- https://github.com/mintoolkit/mint

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/oLy0/Vulnerability

- https://github.com/parth45/cheatsheet

- https://github.com/secLuk3/Penetration-Testing-Project-Unisa-23-24

- https://github.com/securelayer7/CVE-Analysis

- https://github.com/securelayer7/Research

- https://github.com/slimtoolkit/slim

- https://github.com/tanjiti/sec_profile

- https://github.com/tw0point/BadBizness-CVE-2023-51467

- https://github.com/txuswashere/OSCP

- https://github.com/wjlin0/poc-doc

- https://github.com/wooluo/POC00

- https://github.com/wy876/POC

- https://github.com/xingchennb/POC-

- https://github.com/yukselberkay/CVE-2023-49070_CVE-2023-51467