shacojx / POC-CVE-2020-7961-Token-iterate

POC-CVE-2020-7961-Token-iterate
3 stars 1 forks source link

not working #1

Open xumia1 opened 3 years ago

xumia1 commented 3 years ago

hi, thank you for your poc but can you tell me what version of liferay you used ? i tested on liferay 7.0.2 GA3 it not work . the error is {"exception":"<--- java.beans.PropertyVetoException: Failed to parse stringified userOverrides....... "throwable":"jodd.json.JsonException: <--- java.beans.PropertyVetoException: Failed to parse stringified userOverrides. HexAsciiSerializedMap thank you for your help

dabasanta commented 2 years ago

I think that this is not the correct gadget. Will be great if shacojx could include more info and details in your readme file, like what gadget instrumentation is used to build the HexAciiSerializedMap payload that python script send to the server.

I known that yoserial was used, but don't known that gadget is used to do what... Or, how java application read the code from 'cmd2' header and then responds with the output of the system command executed...