.. / CVE-2018-1000129

Exploit for Jolokia 1.3.7 - Cross-Site Scripting (CVE-2018-1000129)

Description:

Jolokia 1.3.7 is vulnerable to cross-site scripting in the HTTP servlet and allows an attacker to execute malicious JavaScript in the victim’s browser.

Nuclei Template

View the template here CVE-2018-1000129.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-1000129.yaml
Copy

References:

https://jolokia.org/#Security_fixes_with_1.5.0
https://github.com/rhuss/jolokia/commit/5895d5c137c335e6b473e9dcb9baf748851bbc5f#diff-f19898247eddb55de6400489bff748ad
https://nvd.nist.gov/vuln/detail/CVE-2018-1000129
https://blog.gdssecurity.com/labs/2018/4/18/jolokia-vulnerabilities-rce-xss.html
https://blog.it-securityguard.com/how-i-made-more-than-30k-with-jolokia-cves/