Skip to content
 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 

Repository files navigation

CVE-2022-29464-Bypass-CloudFlare

WSO2 RCE (CVE-2022-29464) exploit and bypass CloudFlare.

Details

CVE-2022-29464 is critical vulnerability on WSO2 discovered by Orange Tsai. the vulnerability is an unauthenticated unrestricted arbitrary file upload which allows unauthenticated attackers to gain RCE on WSO2 servers via uploading malicious JSP files.

For more details, you can read my blog post below.

The following blog post provides an in-depth analysis of how Cloudflare security measures are bypassed and the methods used in the process. If you want to learn more about the subject, you can check out my post for details.

Medium link

Original repo (without Cloudflare Bypass): https://github.com/hakivvi/CVE-2022-29464 - @hakivvi

Requirements

You can install the Requirements by running the command:

pip install requests

Usage

python3 exploit.py https://host

image

PoC

  • Using Burpsuite: image

image

About

WSO2 RCE (CVE-2022-29464) exploit and bypass CloudFlare.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages