Zum Hauptinhalt springen
••••••
Sichere ProgrammierungRemoveMacAI: apaga Apple Intelligence y libera espacio en disco(05.10.2026 um 04:46 Uhr)
••
Sichere ProgrammierungQuiz Master – An AI-Powered Quiz Learning Companion(05.10.2026 um 04:47 Uhr)
•
Sichere ProgrammierungQuiz master(05.10.2026 um 04:48 Uhr)
•••••••
Sichere ProgrammierungRemoveMacAI: apaga Apple Intelligence y libera espacio en disco(05.10.2026 um 04:46 Uhr)
••
Sichere ProgrammierungQuiz Master – An AI-Powered Quiz Learning Companion(05.10.2026 um 04:47 Uhr)
•
Sichere ProgrammierungQuiz master(05.10.2026 um 04:48 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

AjaxPro Deserialization Remote Code Execution

This Metasploit module leverages an insecure deserialization of data to get remote code execution on the target OS in the context of the user running the…

Beitrag
0
Seite
0
↗ Quelle (packetstormsecurity.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
This Metasploit module leverages an insecure deserialization of data to get remote code execution on the target OS in the context of the user running the website which utilized AjaxPro. To achieve code execution, the module will construct some JSON data which will be sent to the target. This data will be deserialized by the AjaxPro JsonDeserializer and will trigger the execution of the payload. All AjaxPro versions prior to 21.10.30.1 are vulnerable to this issue, and a vulnerable method which can be used to trigger the deserialization exists in the default AjaxPro namespace. AjaxPro 21.10.30.1 removed the vulnerable method, but if a custom method that accepts a parameter of type that is assignable from ObjectDataProvider (e.g. object) exists, the vulnerability can still be exploited. This module has been tested successfully against official AjaxPro on version 7.7.31.1 without any modification, and on version 21.10.30.1 with a custom vulnerable method added.
🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
1 belegte Technik
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
IoC Intelligence
2 Indikatoren · Defanged · STIX 2.1
21[.]10[.]30[.]17[.]7[.]31[.]1
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
6 Knoten · 5 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten AjaxPro Deserialization Remote Code Execution

Thematisch verwandte Begriffe: AjaxPro, Deserialization, Remote, Code · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag