
404 page to RCE. A report by @spaceraccoonsec He chained two old CVEs to achieve RCE: - Found a 404 page mentioning an obscure CMS, discovered /josso/signin login - Triggered CVE-2007-0450 (directory traversal in mod_proxy) using a %5C../ to bypass the internal proxy - Reached an unprotected JBoss web console on localhost (CVE-2007-1036) - Exploited Java deserialization with jexboss tool for full RCE Full report 👇 https://hackerone.com/reports/502758
Post summary
The tweet reports an active exploitation chain using two legacy CVEs, describes the technical steps and a specific exploit tool (jexboss), and links to a full HackerOne report detailing the PoC.
