Collected research
Hunting for security bugs in AEM webapps
A survey of attacks on Adobe Experience Manager: dispatcher filter bypasses using extra slashes and appended extensions, exposed Sling servlets that dump JCR nodes and run arbitrary searches, user enumeration and unthrottled basic-auth brute force. Several servlet SSRFs are escalated to code execution by joining the replication topology, plus SVG XSS, DoS and the aem-hacker toolkit.
Record
- Researcher
- Mikhail Egorov
- Published by
- Speaker Deck
- Date
- Format
- Slides
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Egorov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .