漏洞类别:Web Application
漏洞等级:
漏洞信息
Apache Axis2 is a Web Services/SOAP/WSDL engine.
The instance of Axis2 on the target allows administrative access with default credentials of username "admin" and password as "axis2".
漏洞危害
A remote attacker could exploit this to take control of the Axis2 server and execute arbitrary code by uploading a crafted web service.
解决方案
Change the password for the "admin" account. This can be done by changing parameters in axis2.xml as required. Refer toApache Axis2 Web Administrator's Guide for more information.
0daybank
文章评论