Liferay TunnelServlet Deserialization Remote Code Execution
by darkspeed - Thursday March 13, 2025 at 01:14 AM
#1
Affected Versions:
  • Liferay Portal CE: 7.0 GA3, 7.0.1 GA2, 7.0.2 GA3
  • Liferay Portal EE: 6.0, 6.0 SP1, 6.0 SP2, 6.1 GA1, 6.1 GA2, 6.1 GA3, 6.2
Bypass Technique:
  • Filter Bypass:
    • ////api///////liferay
    • ///api///////spring
    • Nginx Forwarding Fails:
      /#/../api/liferay
PoC Exploit Code:
Hidden Content
You must register or login to view this content.
Reply
#2
(Mar 13, 2025, 01:14 AM)darkspeed Wrote: Affected Versions:
  • Liferay Portal CE: 7.0 GA3, 7.0.1 GA2, 7.0.2 GA3
  • Liferay Portal EE: 6.0, 6.0 SP1, 6.0 SP2, 6.1 GA1, 6.1 GA2, 6.1 GA3, 6.2
Bypass Technique:
  • Filter Bypass:
    • ////api///////liferay
    • ///api///////spring
    • Nginx Forwarding Fails:
      /#/../api/liferay
PoC Exploit Code:
.......................
Reply
#3
(Mar 13, 2025, 01:14 AM)darkspeed Wrote: Affected Versions:
  • Liferay Portal CE: 7.0 GA3, 7.0.1 GA2, 7.0.2 GA3
  • Liferay Portal EE: 6.0, 6.0 SP1, 6.0 SP2, 6.1 GA1, 6.1 GA2, 6.1 GA3, 6.2
Bypass Technique:
  • Filter Bypass:
    • ////api///////liferay
    • ///api///////spring
    • Nginx Forwarding Fails:
      /#/../api/liferay
PoC Exploit Code:

Thanks for sharing...will try this shit out...
Reply
#4
(Mar 13, 2025, 01:14 AM)darkspeed Wrote: Affected Versions:
  • Liferay Portal CE: 7.0 GA3, 7.0.1 GA2, 7.0.2 GA3
  • Liferay Portal EE: 6.0, 6.0 SP1, 6.0 SP2, 6.1 GA1, 6.1 GA2, 6.1 GA3, 6.2
Bypass Technique:
  • Filter Bypass:
    • ////api///////liferay
    • ///api///////spring
    • Nginx Forwarding Fails:
      /#/../api/liferay
PoC Exploit Code:


tttttthanks for your poc
Reply
#5
(Mar 13, 2025, 06:17 AM)Banuk Wrote: Thanks for sharing...will try this shit out...

yeah I found a docker image for liferay 6.1, could be easy for you to build the environment
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 431 25,026 2 hours ago
Last Post: jacksonsmithsa
  New Zer0 Day Wordpress A3g00n 79 2,953 6 hours ago
Last Post: baku
  new wordpress website takeover vuln (video + poc ) zinzeur 314 28,001 6 hours ago
Last Post: baku
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 66 2,973 Yesterday, 08:51 PM
Last Post: Yjuddur
  Acunetix Premium Cracked v24 Full Activated A3g00n 22 1,334 Yesterday, 09:22 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: