Sploitus

Exploit for Deserialization of Untrusted Data in Apache Ofbiz

githubexploit · 2021-03-23

Exploit Code

README12 lines
## https://sploitus.com/exploit?id=DFD57FC3-633C-5613-9AAB-EFE75EBB4A9C
# CVE-2021-26295-POC

This example demonstrates exploiting the CVE-2021-26295 vulnerability using DNSlog. ### Usage

Run `poc: target.txt` to execute the test. (The Jdk environment should be version <12; otherwise, ysoserial may not generate a valid payload.)

Example usage: `python exp.py https://baidu.com`, then enter the command execution interface without any output.

This is for educational purposes only. Do not use it for any other purposes.

[source-iocs-preserved url=https://baidu.com`]