Web Hack List

Collected research

Hello Lucee! Let us hack Apple again?

Lucee, an open-source CFML application server, exposes several paths that evaluate attacker-supplied strings as CFML or deserialise them as Java objects. This case study traces a REST mapping that deserialises request bodies, a client-scope cookie passed to an unrestricted expression interpreter, and ordinary functions such as isDefined() reaching the variable interpreter, the last chained into pre-authentication remote code execution on an Apple host and on Lucee's own update server.

Record

Researcher
Harsh Jaiswal and Rahul Maini
Published by
ProjectDiscovery
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .