.. / CVE-2020-6950

Exploit for Eclipse Mojarra - Local File Read (CVE-2020-6950)

Description:

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Nuclei Template

View the template here CVE-2020-6950.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-6950.yaml
Copy

References:

https://github.com/eclipse-ee4j/mojarra/issues/4571
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
https://www.oracle.com/security-alerts/cpuapr2022.html
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
https://nvd.nist.gov/vuln/detail/CVE-2020-6950