Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-1000027 PoC — Vmware Spring Framework 代码问题漏洞

Source
Associated Vulnerability
Title:Vmware Spring Framework 代码问题漏洞 (CVE-2016-1000027)
Description:Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
Description
Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.
Readme
# spring-web-without-remoting
Spring Web 5.x with `org.springframework.remoting` package removed, to fix <a href="https://github.com/advisories/GHSA-4wrc-f8pq-fpqp">CVE-2016-1000027</a>.

For more info, see <a href="https://github.com/spring-projects/spring-framework/issues/24434">spring-projects/spring-framework #24434</a>.
File Snapshot

[4.0K] /data/pocs/935d5b2233d5c10309345da23c469055e9fc2c54 ├── [ 11K] LICENSE ├── [9.6K] mvnw ├── [6.5K] mvnw.cmd ├── [9.2K] pom.xml └── [ 327] README.md 0 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →