H2O - Arbitrary Path Lookup
H2O allows for arbitrary path lookup via it's Typehead API endpoint
h2oPoC 已收录
CVSS—
共找到 4 条公开漏洞记录
H2O allows for arbitrary path lookup via it's Typehead API endpoint
H2o dashboard by default has no authentication and can lead to RCE on the host.
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.