Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-7609 — Kibana 原型污染 | Kitploit
工具/GitHubGitHub/dnr6419/cve-2019-7609
漏洞分析漏洞利用Web应用程序漏洞利用学习与教育实验室与实践
GitHubdnr6419/cve-2019-7609

CVE-2019-7609

Kibana 原型污染

查看仓库
14年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2019-7609

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer https://nvd.nist.gov/vuln/detail/CVE-2019-7609

CVE-2019-7609

该漏洞是 Kibana 中发现的 Prototype Pollution 漏洞。利用此漏洞可能导致 DoS 或 RCE 攻击。

特点

  • 添加了 Node 提供的 debugging 选项。
  • 可通过 Chrome://inspect 进入并使用调试功能。

安装及运行步骤

1. 安装 Kibana

进行安装时,请在 docker-compose.yml 文件中进行端口转发。

root@kitploit:~
 $ docker-compose up  

2. 调试连接

来源

https://github.com/hekadan/CVE-2019-7609
https://www.cnblogs.com/anyun/p/8458476.html
https://slides.com/securitymb/prototype-pollution-in-kibana/#/41

注意事项

若非法利用上述漏洞,我们概不承担法律责任。

If you illegally exploit the above vulnerabilities, you will not be held liable.

必须将 docker 版本更新到最新。

下载工具