Exposed GoAnywhere MFT are subject to an unfixed 0day RCE and should be considered unsafe when made public.
Severity: critical
Fingerprint: b1a07937af044f4619de6baab5894bf3b5894bf3b5894bf3b5894bf3b5894bf3
Found vulnerable GoAnywhere MFT: Affected by CVE-2023-0669
Fingerprint: b1a07937b9045eb34a1c93d7284e08c8d72a5b0793e6f8eaf8ce3b48fd73df62
HTTP/1.1 302 Set-Cookie: RSESSIONID=7E2860D09C21D408BF8AF824ADDB80E9; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Fri, 03 Feb 2023 02:36:56 GMT Connection: close
Fingerprint: b1a07937a2043ad762b1855ead43096d43c6b7a83652435639b6efe039b6efe0
Set-Cookie: RSESSIONID=9F5D4A62F2B4A79F4289BB557F337DDF; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Fri, 20 Jan 2023 21:36:11 GMT Connection: close
Fingerprint: b1a07937a2043ad7284b5c0f98356f4a0c7e96815641c641a501fa75a501fa75
Set-Cookie: RSESSIONID=E89D39D004743B3EA48D5E9C2D995D68; Path=/; Secure; HttpOnly Location: /goanywhere Content-Type: text/html;charset=UTF-8 Content-Length: 0 Date: Thu, 15 Dec 2022 20:33:41 GMT Connection: close