Web Hack List

Collected research

Hunting for security bugs in AEM webapps

A survey of attacks on Adobe Experience Manager: dispatcher filter bypasses using extra slashes and appended extensions, exposed Sling servlets that dump JCR nodes and run arbitrary searches, user enumeration and unthrottled basic-auth brute force. Several servlet SSRFs are escalated to code execution by joining the replication topology, plus SVG XSS, DoS and the aem-hacker toolkit.

Record

Researcher
Mikhail Egorov
Published by
Speaker Deck
Date
Format
Slides
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mikhail Egorov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .