Web Hack List

Collected research

JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory

A JNDI lookup pointed at a Tomcat user-database factory lets an attacker set its pathname and readonly properties, so the factory fetches attacker-hosted XML and writes it back out to a chosen path. Chaining a bean factory with a directory-creating utility satisfies the writeability check, giving arbitrary file write and remote code execution.

Record

Published by
srcincite.io
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of srcincite.io, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .