本仓库包含一个使用 Docker 对 CVE-2021-23394(elFinder 任意文件执行漏洞)的复现环境。它设置了四个环境,用于对比漏洞版本与修复版本在 Apache 和 Nginx 下的表现。
本环境包含:
8080):elFinder 2.1.57 在 Apache 上运行8081):elFinder 2.1.66 在 Apache 上运行8082):elFinder 2.1.57 在 Nginx 上运行8083):elFinder 2.1.66 在 Nginx 上运行确保设置脚本具有可执行权限(如果尚未设置):
chmod +x setup_containers.sh
运行设置脚本:
./setup_containers.sh
该脚本将构建 Docker 镜像并启动容器。
你可以通过浏览器访问 elFinder 界面,地址为:
要验证漏洞(或修复),请使用 Nuclei 配合相应的模板。
运行以下命令(请将 path-to-nuclei-templates 替换为你的模板目录实际路径):
# 测试 Apache 漏洞版本(应显示存在漏洞)
nuclei -t path-to-nuclei-templates/http/cves/2021/CVE-2021-23394.yaml -u http://localhost:8080
# 测试 Apache 修复版本(应显示不存在漏洞)
nuclei -t path-to-nuclei-templates/http/cves/2021/CVE-2021-23394.yaml -u http://localhost:8081
# 测试 Nginx 漏洞版本(应显示存在漏洞)
nuclei -t path-to-nuclei-templates/http/cves/2021/CVE-2021-23394.yaml -u http://localhost:8082
# 测试 Nginx 修复版本(应显示不存在漏洞)
nuclei -t path-to-nuclei-templates/http/cves/2021/CVE-2021-23394.yaml -u http://localhost:8083
或者,创建一个 targets.txt 文件一次性测试所有目标:
echo -e "http://localhost:8080\nhttp://localhost:8081\nhttp://localhost:8082\nhttp://localhost:8083" > targets.txt
nuclei -t path-to-nuclei-templates/http/cves/2021/CVE-2021-23394.yaml -l targets.txt
预期结果:
要停止并移除容器,你可以运行脚本中的清理命令或手动执行:
docker rm -f elfinder-apache-vuln elfinder-apache-patched elfinder-nginx-vuln elfinder-nginx-patched