
PoC for CVE-2022-26134, a Confluence Server OGNL injection vulnerability, built on the pocsuite3 framework for authorized security testing.
git clone https://github.com/CJ-0107/cve-2022-26134
cd cve-2022-26134
This tool is a POC written based on the pocsuite3 framework development specification.
Please download pocsuite3 before use.
Project address
https://github.com/knownsec/pocsuite3
Environment
Python 3.7+
Works on Linux, Windows, Mac OSX, BSD, etc.
pip installation
pip3 install pocsuite3
# use other pypi mirror
pip3 install -i https://pypi.tuna.tsinghua.edu.cn/simple pocsuite3
POC
pocsuite -r pocs/cve-2021-46422.py -f cve-2022-26134.txt
This tool is only intended for legally authorized enterprise security building activities. If you need to test the usability of this tool, please set up your own test environment.
When using this tool for detection, you should ensure that the behavior complies with local laws and regulations, and that you have obtained sufficient authorization. Do not scan unauthorized targets.
If you engage in any illegal behavior while using this tool, you must bear the corresponding consequences. We will not assume any legal or joint liability.