.. / CVE-2019-8086

Exploit for Adobe Experience Manager - XML External Entity Injection (CVE-2019-8086)

Description:

Adobe Experience Manager 6.5, 6.4, 6.3 and 6.2 are susceptible to XML external entity injection. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2019-8086.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-8086.yaml
Copy

References:

https://helpx.adobe.com/security/products/experience-manager/apsb19-48.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-8086
https://nvd.nist.gov/vuln/detail/CVE-2019-8086
https://speakerdeck.com/0ang3el/a-hackers-perspective-on-aem-applications-security?slide=13
https://github.com/0ang3el/aem-hacker/blob/master/aem_hacker.py