Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2023-49070 PoC — Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

Source
Associated Vulnerability
Title:Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present (CVE-2023-49070)
Description:Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10
Description
Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.
Readme
# Exploit CVE-2023-49070 and CVE-2023-51467 Apache OFBiz < 18.12.10
**Authentication Bypass Vulnerability Apache OFBiz**

This exploit code has been developed solely for educational purposes and to enhance cybersecurity practices. Any use for illicit purposes is entirely your own responsibility. It is recommended to use it only in environments where explicit authorization is granted to avoid any ethical or legal violations.

To execute this exploit, it is necessary to download the `ysoserial-all.jar` file. The following command can assist you with this:
<p>wget https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar</p>

**References:**
- [CVE-2023-49070](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49070)
- [CVE-2023-51467](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-51467)
- [CVE-2023-49070 and CVE-2023-51467 Exploit](https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467-exploit)
File Snapshot

[4.0K] /data/pocs/d4975b62a5f45e982cc8b91b94c6be503c450146 ├── [4.0K] ofbiz_exploit.py └── [1010] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →