You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, according to the documentation of Apache Axis2, the administration console has default credentials that if not changed allow an attacker to upload new services thus leading to RCE.
I would like to develop a plugin for Apache Axis2 instances that functions as a weak credential tester.
Hi, according to the documentation of Apache Axis2, the administration console has default credentials that if not changed allow an attacker to upload new services thus leading to RCE.
I would like to develop a plugin for Apache Axis2 instances that functions as a weak credential tester.
Apache Axis2 Default Credentials:
https://axis.apache.org/axis2/java/core/docs/webadminguide.html
RCE through uploaded plugin:
https://medium.com/@domenicoveneziano/hidden-in-plain-sight-uncovering-rce-on-a-forgotten-axis2-instance-86ddc91f1415
The text was updated successfully, but these errors were encountered: