π‘time
JSON | JSON DESERIALIZATION | com.fasterxml.jackson | PUBLIC EXPLOIT | SSRF TO RCE |
Recon & Enum
Port scan
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))Directory scan
WEB (80)
Validation failed: Unhandled Java exception: com.fasterxml.jackson.databind.exc.MismatchedInputException: Unexpected token (START_OBJECT), expected START_ARRAY: need JSON Array to contain As.WRAPPER_ARRAY type information for class java.lang.ObjectShell as pericles
privesc pericles => root
Last updated