Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Apache Solr | Apache Solr 5.0.0 to Apache Solr 8.3.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool. | https://github.com/SDNDTeam/CVE-2019-17558_Solr_Vul_Tool | POC Details |
| 2 | Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340 | https://github.com/zhzyker/exphub | POC Details |
| 3 | Solr_CVE-2019-17558 | https://github.com/Ma1Dong/Solr_CVE-2019-17558 | POC Details |
| 4 | Apache Solr 1.4 Injection to get a shell | https://github.com/xkyrage/Exploit_CVE-2019-17558-RCE | POC Details |
| 5 | CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool. | https://github.com/thelostworldFree/CVE-2019-17558_Solr_Vul_Tool | POC Details |
| 6 | Apache Solr versions 5.0.0 to 8.3.1 are vulnerable to remote code execution vulnerabilities through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/ directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17558.yaml | POC Details |
| 7 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20Solr%20Velocity%20%E6%B3%A8%E5%85%A5%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-17558.md | POC Details |
| 8 | https://github.com/vulhub/vulhub/blob/master/solr/CVE-2019-17558/README.md | POC Details | |
| 9 | None | https://github.com/rogerzeferino/Apache-Solr-RCE-CVE-2019-17558 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-20493 | GitLab 安全漏洞 | |
| CVE-2019-20165 | GPAC 代码问题漏洞 | |
| CVE-2019-20162 | GPAC 缓冲区错误漏洞 | |
| CVE-2019-20163 | GPAC 代码问题漏洞 | |
| CVE-2019-20164 | GPAC 代码问题漏洞 | |
| CVE-2018-20498 | GitLab 访问控制错误漏洞 | |
| CVE-2018-20497 | GitLab 代码问题漏洞 | |
| CVE-2018-20496 | GitLab 跨站脚本漏洞 | |
| CVE-2018-20495 | GitLab 信息泄露漏洞 | |
| CVE-2018-20494 | GitLab 访问控制错误漏洞 | |
| CVE-2018-20499 | GitLab 代码问题漏洞 | |
| CVE-2018-20491 | GitLab 跨站脚本漏洞 | |
| CVE-2018-20490 | GitLab 跨站脚本漏洞 | |
| CVE-2018-20489 | GitLab 授权问题漏洞 | |
| CVE-2018-20488 | GitLab 信息泄露漏洞 | |
| CVE-2018-7859 | D-Link DGS-1510 跨站脚本漏洞 | |
| CVE-2019-19032 | XMLBlueprint 代码问题漏洞 | |
| CVE-2019-19031 | Easy XML Editor 代码问题漏洞 | |
| CVE-2019-20149 | kind-of 注入漏洞 | |
| CVE-2019-13445 | ROS communications-related packages 输入验证错误漏洞 |
Showing top 20 of 65 CVEs. View all on vendor page → →
No comments yet