GeoServer: Full Exploit + Mass Scanning Utility
by Loki - Sunday August 4, 2024 at 08:03 PM
#11
(Aug 04, 2024, 08:03 PM)Loki Wrote:
GeoServer is an open-source Java-based software server that enables users to view, edit, and share geospatial data. It offers a versatile and efficient solution for distributing geospatial information from various sources such as GIS databases, web-based data, and personal datasets.
In versions of GeoServer earlier than 2.23.2, 2.23.6, versions 2.24.0 to 2.24.3, and version 2.25.0, there exists a vulnerability (CVE-2024-36401) that permits Remote Code Execution (RCE) by unauthenticated users. This issue arises from the unsafe evaluation of property names as XPath expressions in multiple OGC request parameters.
Exploiting this vulnerability, an attacker can send a POST request containing a malicious XPath expression, which can result in arbitrary command execution as root on the system running GeoServer.

cheersssssssssssssss
Reply
#12
hope it work thanks .
Reply
#13
oh nice 1!! thanks for sharing
Reply
#14
Thank you bro for the tool you have provded to me

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#15
nice, I need to knoww this
Reply
#16
fgggggggggggggggggggggggggggggggggggggggggggggggs

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Spamming | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#17
Well, lets se what is behind
Reply
#18
Thanks so much bro, this is a very useful tutorial.
Reply
#19
thank you for sharing this
Reply
#20
Good information, thanks for sharing my brother
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 438 26,847 2 hours ago
Last Post: NUKEx
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 108 13,821 Yesterday, 05:42 PM
Last Post: nobcoderfck
  Ban Any Discord Exploit phineasfisherman 7 475 Yesterday, 10:16 AM
Last Post: sniperx86
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 42 3,785 Yesterday, 08:39 AM
Last Post: d39ug
  New Zer0 Day Wordpress A3g00n 81 3,418 May 05, 2026, 03:06 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)