CVE-2024-36104 的概念验证利用脚本,针对 Apache OFBiz 18.12.14 之前版本中的未认证远程代码执行漏洞。

Stars

3

7 天增长

暂无数据

Fork 数

0

开放 Issue

0

开源协议

MIT

最近更新

2026-07-29

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

该仓库提供了一个清晰且功能完整的脚本,通过路径穿越和 Groovy 代码执行实现了关键的未授权 RCE,并附有详细的技术说明和可定制的选项。

适合谁使用

  • 安全研究人员
  • 渗透测试人员
  • Apache OFBiz 管理员
  • 红队成员

典型使用场景

  • 在测试环境中验证 CVE-2024-36104
  • 向管理层演示路径穿越与 Groovy RCE 的危害
  • 评估 OFBiz 环境中的补丁合规性
  • 安全培训与 CTF 练习

项目优势

  • 对漏洞机制和利用步骤有清晰的文档说明
  • 支持通过可选参数进行定制(如 Host 头、视图路径、混淆)
  • 依赖少,使用简单,仅需 Python 3.8+
  • 提供混淆选项以绕过基础 WAF 签名

使用前须知

  • 仅适用于 Apache OFBiz 18.12.14 之前的版本
  • 即使使用混淆,仍可能被现代 WAF 拦截
  • 命令输出提取依赖于解析服务器返回的 HTML 错误页面

README 快速开始

Quick Start

项目描述

PoC for CVE-2024-36104 — unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path traversal to ProgramExport

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

lopopolo
精选
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI 与机器学习AI 智能体
2,390
slvDev
精选
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI 与机器学习大语言模型
1,960
littledivy
精选
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI 与机器学习
1,482