[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":43,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":50,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":56,"vulnerability-29503":63},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":42,"variant":13,"campaign_id":30},"DEF CON AI pentests launch","def-con-ai-pentests","We’re launching AI Pentests at DEF CON 34","https://pentest-tools.com/events/defcon-34-2026",[34,35,36,37,38,39,40,41],"/","/website-vulnerability-scanning/website-scanner","/network-vulnerability-scanning/network-security-scanner-online","/information-gathering/find-subdomains-of-domain","/network-vulnerability-scanning/port-scanner-online-nmap","/product","/website-vulnerability-scanning/discover-hidden-directories-and-files","/insights","See you there",["Island",44],{"key":45,"params":46,"result":48},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":47},"{}",{"head":49},{},["Island",51],{"key":52,"params":53,"result":54},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":47},{"head":55},{},["Island",57],{"key":58,"params":59,"result":61},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":60},"{\"text-color\":\"gray\"}",{"head":62},{},{"id":64,"detectable_with":65,"vuln_details":71,"vuln_id":95,"name":96,"published":97,"updated":97},29503,{"tool":66,"engine":69},{"id":67,"name":68},1,"Network Scanner",{"id":67,"name":70},"Sniper",{"id":64,"codename":72,"description":73,"severity":74,"risk_description":75,"public_description":76,"public_recommendation":77,"recommendation":78,"references":79,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":88,"date":89,"software_type":90,"vendor":91,"product":92,"ptt_exploit_capabilities":93},null,"We found that the target server is running ForgeRock AM/OpenAM, a version affected by CVE-2021-35464. The vulnerability stems from unauthenticated Java deserialization in the jato.pageSession parameter, exposed via multiple pages of the Sun ONE Application Framework (JATO) used by the product's console. By sending a single crafted request to a /ccversion/* endpoint (using a path traversal via a matrix parameter to bypass the authentication filter), an unauthenticated attacker can trigger deserialization of an attacker-controlled Java object graph, leading to remote code execution in the context of the AM/OpenAM process. This only affects builds running on Java 8 or earlier, since JATO relies on classes removed in Java 9.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","ForgeRock AM (and its OpenAM predecessor) prior to version 7.0 (AM branch fixed in 6.5.4, OpenAM branch fixed in 14.6.3) contain a Java deserialization vulnerability in the JATO framework, reachable via the jato.pageSession parameter on multiple unauthenticated pages. An attacker can send a single crafted request to a /ccversion/* endpoint to trigger remote code execution without any authentication, fully compromising the affected server.","Upgrade ForgeRock AM/OpenAM to version 7.0 or later.","We recommend upgrading ForgeRock AM/OpenAM to version 7.0 or later (or the patched 6.5.4/14.6.3 builds) as provided by the vendor; apply any vendor-supplied patches or mitigations immediately.",[80,81,82],"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35464","http://packetstormsecurity.com/files/163525/ForgeRock-Access-Manager-OpenAM-14.6.3-Remote-Code-Execution.html","https://bugster.forgerock.org",9.8,0.99999,0.99993,[87],"CVE-2021-35464",true,"2021-07-22T00:00:00Z","Identity and Access Management (IAM) / SSO Server","ForgeRock","AM / OpenAM",[94],"RCE","NETSCAN-SNIPER-CVE-2021-35464","ForgeRock AM/OpenAM - Remote Code Execution","2026-08-04T00:00:00Z"]