Exposed GoAnywhere MFT are subject to an unfixed 0day RCE and should be considered unsafe when made public.
Severity: critical
Fingerprint: b1a07937af044f4619de6baafb4635b9fb4635b9fb4635b9fb4635b9fb4635b9
Found vulnerable GoAnywhere MFT: Affected by CVE-2024-0204
Severity: critical
Fingerprint: b1a07937af044f4619de6baab5894bf3b5894bf3b5894bf3b5894bf3b5894bf3
Found vulnerable GoAnywhere MFT: Affected by CVE-2023-0669
Fingerprint: b1a07937b9045eb34a1c93d7b44b587a7c498e716b9f991c073e241257cc6808
HTTP/1.1 302 Set-Cookie: RSESSIONID=68253D5760A88CFC37E34992BD24E85B; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Fri, 03 Feb 2023 14:47:44 GMT Connection: close Strict-Transport-Security: max-age=16070401; includeSubDomains
Fingerprint: b1a07937a2043ad7cede88646cdd8aebed4c6cbe64dadef403db639610797f86
Set-Cookie: RSESSIONID=6FB6703E0F6E785AD99EB92D590421E6; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Tue, 17 Jan 2023 22:42:26 GMT Connection: close Strict-Transport-Security: max-age=16070401; includeSubDomains
Fingerprint: b1a07937a2043ad7dc28df24e4f4642b29c370fe31f28034027835d61ffb5cc6
Set-Cookie: RSESSIONID=DE96C738D0B687B56D3237C9007FFCBA; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Tue, 13 Dec 2022 01:21:41 GMT Connection: close Strict-Transport-Security: max-age=16070401; includeSubDomains
Fingerprint: b1a07937a2043ad79c2c8754ea203ddb5636908ed2994dc412c714a6d95c5a76
Set-Cookie: RSESSIONID=54B3BB9E9FE29BF6E7AF4E92EDFA06DC; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Sat, 19 Nov 2022 10:44:27 GMT Connection: close Strict-Transport-Security: max-age=16070401; includeSubDomains