
在受影响的Confluence Server 和Data Center 版本中,存在一个OGNL 注入漏洞,该漏洞允许未经身份验证的攻击者在Confluence Server 或Data Center 服务器上执行任意代码。
git clone https://github.com/yigexioabai/CVE-2021-46422-RCE.git
cd CVE-2022-26134-cve1
pip3 install -r requirements.txt
Place CVE-2021-46422 RCE.py into the pocsuite3\pocs directory
cd pocs
Single URL:
pocsuite -r CVE-2021-46422 RCE.py -u url
Multiple URLs:
pocsuite -r CVE-2021-46422 RCE.py -f url.txt (file containing URLs) --verify
This tool is intended only for legitimate enterprise security assessments. If you need to test its functionality, please set up your own testing environment.
When using this tool for scanning, you must ensure that such actions comply with local laws and regulations and that you have obtained proper authorization. Do not scan unauthorized targets.
If you engage in any illegal activities while using this tool, you shall bear the corresponding consequences. We assume no legal or joint liability.