CVE-2023-0669
CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
File Explorer
Download Latest Version (.zip)- .gitignore
- encodings.xml
- misc.xml
- uiDesigner.xml
- vcs.xml
- Cryptor.java
- Http.java
- Authors.java
- Dependencies.java
- BASE64Decoder.java
- ClassFiles.java
- CommonUtil.java
- DirtyDataWrapper.java
- Gadgets.java
- PayloadRunner.java
- Reflections.java
- CommonsBeanutils1.java
- ObjectPayload.java
- ReleaseableObjectPayload.java
- ExecCheckingSecurityManager.java
- Deserializer.java
- GeneratePayload.java
- Serializer.java
- Strings.java
- YsoConfig.java
- Exploit.java
- GenerateEvilPayload.java
- .gitignore
- burp.png
- LICENSE
- pom.xml
- rce-demo.png
- README.md
# Installation Guide
1. Get the code
git clone https://github.com/0xf4n9x/CVE-2023-0669
Downloads the entire project code from GitHub to your computer.
cd CVE-2023-0669
Moves into the project folder you just downloaded.
2. Maven (Java)
Medium RecommendedPrerequisites
- Git Needed to download the project code from GitHub.
- JDK (Java) Required to build and run Java projects.
- Maven The build tool used for the mvn command.
mvn clean install
Installs dependencies and builds the project using Maven.
A BUILD SUCCESS message means it worked. The output is created under target/.
// repository documentation
Was this content helpful?
(0 ratings)
