Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-49070 PoC — Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

Source
Associated Vulnerability
Title:Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present (CVE-2023-49070)
Description:Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10
Description
Exploit Of Pre-auth RCE in Apache Ofbiz!!
Readme
<h1 align="center">
    CVE-2023-49070
  <br>
</h1>
<h4 align="center">Pre-auth RCE in Apache Ofbiz!!</h4>
    <p align="center">
  <a href="https://github.com/0xrobiul/CVE-2023-49070">
    <img src="https://img.shields.io/static/v1?label=Project&message=CVE-2023-49070&color=green">
  </a>
  <a href="https://twitter.com/0xrobiul">
      <img src="https://img.shields.io/twitter/follow/0xrobiul?style=social">
  </a>
  <a href="https://youtu.be/gDzYb6YvBSQ">
      <img src="https://img.shields.io/youtube/views/gDzYb6YvBSQ?style=social">
  </a>
  <a href="https://github.com/0xrobiul/CVE-2023-49070">
    <img src="https://img.shields.io/static/v1?label=Version&message=1.0&color=green">
  </a>
</p>
<h1 align="center">
  <br>
  <a href="https://github.com/0xrobiul/CVE-2023-49070"><img src="/Intro.png" alt="CVE-2023-49070"></a>
  <br>
  <br>
</h1>
<h1>Usagse</h1>
<h2>Install Open JDK 11 First!</h2>
<pre>
sudo apt install openjdk-11-jdk
</pre>
<h1 align="center">
  <br>
  <a href="https://github.com/0xrobiul/CVE-2023-49070"><img src="/POC.png" alt="Usagse"></a>
  <br>
  <br>
</h1>
Check POC Video: https://youtu.be/gDzYb6YvBSQ
File Snapshot

[4.0K] /data/pocs/d0dc60ee7a76458d0387bd508aebfc15cd6118b7 ├── [1.8K] CVE-2023-49070.py ├── [ 11K] Intro.png ├── [ 34K] LICENSE ├── [201K] POC.png ├── [1.1K] README.md └── [ 57M] ysoserial-all.jar 0 directories, 6 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →