Exploiting SiteCore arbitrary file read (CVE-2023-33651)

Exploiting SiteCore arbitrary file read (CVE-2023-33651)

OS

2024.1.*
2020.3.*
2019.4.*

Apps

S
SitecoreSitecore
8.2.*
8.1.*
10.1.*
1.5.*

Screenshots from the blog posts

images/clzgslafx59w01in93ko0b8bp.jpgimages/clzgslafx59w01in93ko0b8bp.jpg

Summary

In this post, we will uncover the exploit script to pwn vulnerable SiteCore instances and read the files of attacker's choosing from the target servers web root directory and displaying its contents.

general

Description

@secatgourity

190 posts

Total vcoins

0

Social media links

Comments (0)