
CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.
At the end of October 2019, the Solr Velocity template injection remote command execution vulnerability was disclosed. Manual detection of this vulnerability requires several rounds of capturing and modifying packets with Burp, which is inefficient. I wrote this small tool to support one-click vulnerability detection, command execution, and reverse shell. Issues are welcome. This tool is only for security professionals to use within the scope permitted by laws and regulations. Any misuse is at your own risk.
Cross-platform, JRE >= 1.8.
(To reduce file size, the SWT library is packaged separately for each platform; just download the JAR for your platform.)
Windows: java -jar SolrVulScan1.0-win64.jar
Linux: java -jar SolrVulScan1.0-linux64.jar
macOS: java -jar -XstartOnFirstThread SolrVulScan1.0-mac64.jar

Please go to the official website to download the latest version: http://lucene.apache.org/solr/downloads.html