Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-17558 PoC — Apache Solr 注入漏洞

Source
Associated Vulnerability
Title:Apache Solr 注入漏洞 (CVE-2019-17558)
Description:Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
Description
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
File Snapshot

[4.0K] /data/pocs/127523b4627550be0abd8443c9d59e7433857a18 ├── [4.0K] drupal │   ├── [2.2K] cve-2018-7600_cmd.py │   ├── [9.1K] cve-2018-7600_poc.py │   ├── [4.9K] cve-2018-7602_cmd.py │   ├── [9.1K] cve-2018-7602_poc.py │   ├── [3.6K] cve-2019-6340_cmd.py │   └── [5.6K] readme.md ├── [4.0K] f5 │   ├── [1.8K] cve-2020-5902.py │   ├── [4.0K] image │   │   └── [392K] 20200708_2.png │   └── [1.0K] readme.md ├── [4.0K] fastjson │   ├── [ 662] Exploit.java │   ├── [1.7K] fastjson-1.2.24_rce.py │   ├── [1.6K] fastjson-1.2.41_rce.py │   ├── [1.7K] fastjson-1.2.42_rce.py │   ├── [1.6K] fastjson-1.2.43_rce.py │   ├── [1.7K] fastjson-1.2.45_rce.py │   ├── [1.8K] fastjson-1.2.47_rce.py │   ├── [1.6K] fastjson-1.2.62_rce.py │   ├── [2.0K] fastjson-1.2.66_rce.py │   ├── [ 19M] fastjson_tool.jar │   ├── [ 41M] marshalsec-0.0.3-SNAPSHOT-all.jar │   └── [1.6K] readme.md ├── [4.0K] jboss │   ├── [9.9K] cve-2017-12149_cmd.py │   └── [1.4K] cve-2017-12149_poc.py ├── [4.0K] nexus │   ├── [8.5K] cve-2019-7238_cmd.py │   ├── [7.4K] cve-2020-10199_cmd.py │   ├── [2.3K] cve-2020-10199_poc.py │   ├── [2.2K] cve-2020-10204_cmd.py │   └── [1.9K] cve-2020-11444_exp.py ├── [4.0K] ofbiz │   └── [ 16K] cve-2021-26295_rce.py ├── [ 11K] readme.md ├── [4.0K] shiro │   ├── [4.0K] image │   │   ├── [7.4M] 1.gif │   │   ├── [6.2M] 2.gif │   │   ├── [1.2M] linux-rce.gif │   │   ├── [1.3M] linux-shell.gif │   │   └── [1.2M] windows-rce.gif │   ├── [1.7K] readme.md │   ├── [6.1K] shiro-1.2.4_rce.py │   └── [ 54M] ysoserial-sleep.jar ├── [4.0K] solr │   ├── [2.6K] cve-2017-12629_cmd.py │   ├── [3.6K] cve-2019-0193_cmd.py │   └── [2.4K] cve-2019-17558_cmd.py ├── [4.0K] spring │   └── [2.1K] cve-2018-1273_cmd.py ├── [4.0K] struts2 │   ├── [1.8K] readme.md │   ├── [2.3K] struts2-032_cmd.py │   ├── [1.5K] struts2-032_poc.py │   ├── [2.3K] struts2-045-2_cmd.py │   ├── [2.9K] struts2-045_cmd.py │   ├── [3.3K] struts2-052_cmd.py │   ├── [3.4K] struts2-052_webshell.py │   ├── [2.3K] struts2-053_cmd.py │   └── [2.8K] struts2-057_cmd.py ├── [4.0K] tomcat │   ├── [2.2K] cve-2017-12615_cmd.py │   └── [ 11K] cve-2020-1938_exp.py └── [4.0K] weblogic ├── [1.6K] cve-2014-4210_ssrf_redis_shell.py ├── [3.2K] cve-2014-4210_ssrf_scan.py ├── [6.1K] cve-2017-10271_poc.jar ├── [3.8K] cve-2017-10271_webshell.jar ├── [2.3K] cve-2017-3506_poc.py ├── [ 11K] cve-2017-3506_webshell.jar ├── [7.4K] cve-2018-2628_poc.py ├── [9.5K] cve-2018-2628_webshell.py ├── [9.2K] cve-2018-2893_cmd.py ├── [7.3K] cve-2018-2893_poc.py ├── [4.5K] cve-2018-2894_poc_exp.py ├── [4.7K] cve-2019-2618_webshell.py ├── [3.4K] cve-2020-14882_rce.py ├── [2.4K] cve-2020-2551_poc.py ├── [ 11K] cve-2020-2555_cmd.py ├── [9.7K] cve-2020-2883_cmd.py ├── [4.0K] image │   └── [1.5M] cve-2014-4210_ssrf_redis_shell.png └── [ 15K] readme.md 15 directories, 71 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →