J2EEScan icon indicating copy to clipboard operation
J2EEScan copied to clipboard

Update JKStatus.java to bypass restrictions

Open spwn3r49sd3r00 opened this issue 1 year ago • 0 comments

For vulnerable targets, I have observed J2EEScan in Burpsuite does not detect JK endpoints with forbidden or restricted access. Appending a semi-colon at those endpoints will result in a bypass and should likely be detected by the scanner. Reference: https://www.immunit.ch/en/blog/2018/11/02/cve-2018-11759-apache-mod_jk-access-control-bypass/

spwn3r49sd3r00 avatar Mar 29 '23 08:03 spwn3r49sd3r00