Ivanti
Ivanti products - public exploits
Last updated
Ivanti products - public exploits
Last updated
Ivanti EPMM Pre-Auth RCE Chain
Impacting versions 6.3.1, 6.4.0 (tested), 6.4.1, and 6.3.4.
payload encoded base64:
send it to /dana-na/auth/saml-sso.cgi
with SAMLRequest
parm
I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.
The go-to manual for web app pentesters. Covers XSS, SQLi, logic flaws, and more
Learn how to perform reconnaissance on a target, how to identify vulnerabilities, and how to exploit them
Learn about the most common types of bugs like cross-site scripting, insecure direct object references, and server-side request forgery.