Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Druid | 0.20.0 and earlier ~ 0.20.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache Druid 远程代码执行;检测脚本 | https://github.com/yaunsky/cve-2021-25646 | POC Details |
| 2 | None | https://github.com/lp008/CVE-2021-25646 | POC Details |
| 3 | CSharp CVE-2021-25646-GUI | https://github.com/Ormicron/CVE-2021-25646-GUI | POC Details |
| 4 | None | https://github.com/Vulnmachines/Apache-Druid-CVE-2021-25646 | POC Details |
| 5 | Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE | https://github.com/1n7erface/PocList | POC Details |
| 6 | CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本 | https://github.com/givemefivw/CVE-2021-25646 | POC Details |
| 7 | Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646 | https://github.com/j2ekim/CVE-2021-25646 | POC Details |
| 8 | CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具 | https://github.com/luobai8/CVE-2021-25646-exp | POC Details |
| 9 | Apache Druid 远程代码执行复现(CVE-2021-25646) | https://github.com/gps1949/CVE-2021-25646 | POC Details |
| 10 | Apache Druid is susceptible to remote code execution because by default it lacks authorization and authentication. Attackers can send specially crafted requests to execute arbitrary code with the privileges of processes on the Druid server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25646.yaml | POC Details |
| 11 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E6%95%B0%E6%8D%AE%E5%BA%93%E6%BC%8F%E6%B4%9E/Apache%20Druid%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2021-25646.md | POC Details |
| 12 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E6%95%B0%E6%8D%AE%E5%BA%93%E6%BC%8F%E6%B4%9E/Apache%20Druid%20%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2021-25646.md | POC Details |
| 13 | https://github.com/vulhub/vulhub/blob/master/apache-druid/CVE-2021-25646/README.md | POC Details | |
| 14 | CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具 | https://github.com/k7pro/CVE-2021-25646-exp | POC Details |
| 15 | A proof-of-concept for the CVE-2021-25646, which allows for Command Injection | https://github.com/tiemio/RCE-PoC-CVE-2021-25646 | POC Details |
| 16 | Exploit for Apache Druid Embedded Javascript Remote Code Execution (CVE-2021-25646), Python. | https://github.com/ShadowLance2/Apache-Druid-CVE-2021-25646-Exploit | POC Details |
No public POC found.
Login to generate AI POCNo comments yet