POC of CVE-2021-26084, which is Atlassian Confluence Server OGNL Pre-Auth RCE Injection Vulneralibity.

Overview

CVE-2021-26084


Description

  • POC of CVE-2021-26084, which is Atlassian Confluence Server OGNL(Object-Graph Navigation Language) Pre-Auth RCE Injection Vulneralibity.
  • create by antx at 2022-01-13.

Detail

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an authenticated user, and in some instances an unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance. The vulnerable endpoints can be accessed by a non-administrator user or unauthenticated user if โ€˜Allow people to sign up to create their accountโ€™ is enabled. To check whether this is enabled go to COG > User Management > User Signup Options.

CVE Severity

  • attackComplexity: LOW
  • attackVector: NETWORK
  • availabilityImpact: HIGH
  • confidentialityImpact: HIGH
  • integrityImpact: HIGH
  • privilegesRequired: NONE
  • scope: UNCHANGED
  • userInteraction: NONE
  • version: 3.1
  • baseScore: 9.8
  • baseSeverity: CRITICAL

Affect

  • before version 6.13.23
  • from version 6.14.0 before 7.4.11
  • from version 7.5.0 before 7.11.6
  • from version 7.12.0 before 7.12.5

POC


Reference

IMPORTANT

  • This exploit is only intended to facilitate demonstrations of the vulnerability by researchers. I disapprove of illegal actions and take no responsibility for any malicious use of this script. The proof of concept demonstrated in this repository does not expose any hosts and was performed with permission.
Owner
antx
RCT(Reading, Coding and Trading)
antx
Password database With special stuff

This is a Password database I made for myself, as I want to keep all my passwords in the same place. but still protected, shall anyone get access to the file. And so I made this simple password datab

9 Oct 30, 2022
ssh-audit is a tool for ssh server & client configuration auditing.

SSH server & client auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

Joe Testa 1.4k Dec 31, 2022
It's a simple tool for test vulnerability shellshock

Shellshock, also known as Bashdoor, is a family of security bugs in the Unix Bash shell, the first of which was disclosed on 24 September 2014. Shellshock could enable an attacker to cause Bash to ex

Mr. Cl0wn - H4ck1ng C0d3r 88 Dec 23, 2022
Vulnerability Exploitation Code Collection Repository

Introduction expbox is an exploit code collection repository List CVE-2021-41349 Exchange XSS PoC = Exchange 2013 update 23 = Exchange 2016 update 2

0x0021h 263 Feb 14, 2022
Visius Heimdall is a tool that checks for risks on your cloud infrastructure

Heimdall Cloud Checker ๐Ÿ‡ง๐Ÿ‡ท About Visius is a Brazilian cybersecurity startup that follows the signs of the crimson thunder ;) ๐ŸŽธ ! As we value open s

visius 48 Jun 20, 2022
Show apps recorded storage files by jailbreak

0x101 Show registered storage files of apps by jailbreak Legal disclaimer: Usage of insTof for attacking targets without prior mutual consent is illeg

0x 4 Oct 24, 2022
EyeJoๆ˜ฏไธ€ๆฌพ่‡ชๅŠจๅŒ–่ต„ไบง้ฃŽ้™ฉ่ฏ„ไผฐๅนณๅฐ๏ผŒๅฏไปฅๅๅŠฉ็”ฒๆ–นๅฎ‰ๅ…จไบบๅ‘˜ๆˆ–ไน™ๆ–นๅฎ‰ๅ…จไบบๅ‘˜ๅฏนๆŽˆๆƒ็š„่ต„ไบงไธญ่ฟ›่กŒๆŽ’ๆŸฅ๏ผŒๅฟซ้€Ÿๅ‘็Žฐๅญ˜ๅœจ็š„่–„ๅผฑ็‚นๅ’Œๆ”ปๅ‡ป้ขใ€‚

EyeJo EyeJoๆ˜ฏไธ€ๆฌพ่‡ชๅŠจๅŒ–่ต„ไบง้ฃŽ้™ฉ่ฏ„ไผฐๅนณๅฐ๏ผŒๅฏไปฅๅๅŠฉ็”ฒๆ–นๅฎ‰ๅ…จไบบๅ‘˜ๆˆ–ไน™ๆ–นๅฎ‰ๅ…จไบบๅ‘˜ๅฏนๆŽˆๆƒ็š„่ต„ไบงไธญ่ฟ›่กŒๆŽ’ๆŸฅ๏ผŒๅฟซ้€Ÿๅ‘็Žฐๅญ˜ๅœจ็š„่–„ๅผฑ็‚นๅ’Œๆ”ปๅ‡ป้ขใ€‚ ๅ…่ดฃๅฃฐๆ˜Ž ๆœฌๅนณๅฐ้›†ๆˆไบ†ๅคง้‡็š„ไบ’่”็ฝ‘ๅ…ฌๅผ€ๅทฅๅ…ท๏ผŒไธป่ฆๆ˜ฏๆ–นไพฟๅฎ‰ๅ…จไบบๅ‘˜ๆ•ด็†ใ€ๆŽ’ๆŸฅ่ต„ไบงใ€ๅฎ‰ๅ…จๆต‹่ฏ•็ญ‰๏ผŒๅˆ‡ๅ‹ฟ็”จไบŽ้žๆณ•็”จ้€”ใ€‚ไฝฟ็”จ่€…ๅญ˜ๅœจๅฑๅฎณ็ฝ‘็ปœๅฎ‰ๅ…จ็ญ‰ไปปไฝ•้žๆณ•่กŒไธบ๏ผŒๅŽๆžœ่‡ช่ดŸ๏ผŒไฝœ

429 Dec 31, 2022
A compact version of EDI-Vetter, which uses the TLS output to quickly vet transit signals.

A compact version of EDI-Vetter, which uses the TLS output to quickly vet transit signals. All your favorite hits in a simplified format.

Jon Zink 2 Aug 03, 2022
Malware Configuration And Payload Extraction

CAPEv2 (Python3) has now been released CAPEv2 With the imminent end-of-life for Python 2 (January 1 2020), CAPEv1 will be phased out. Please upgrade t

Context Information Security 701 Dec 27, 2022
A fully automated, accurate, and extensive scanner for finding vulnerable log4j hosts

log4j-scan A fully automated, accurate, and extensive scanner for finding vulnerable log4j hosts Features Support for lists of URLs. Fuzzing for more

Duc Linh Nguyen 4 Aug 08, 2022
A Superfast SMS & Call bomber for Linux And Termux !

A Superfast SMS & Call bomber for Linux And Termux !

Anubhav Kashyap 15 Feb 21, 2022
ไธ€ๆฌพ้’ˆๅฏนๅ‘ๆ—ฅ่‘ต็š„่ฏ†ๅˆซ็ ๅ’Œ้ชŒ่ฏ็ ๆๅ–ๅทฅๅ…ท

Sunflower_get_Password ไธ€ๆฌพ้’ˆๅฏนๅ‘ๆ—ฅ่‘ต็š„่ฏ†ๅˆซ็ ๅ’Œ้ชŒ่ฏ็ ๆๅ–ๅทฅๅ…ท ๐Ÿ‘ฎ๐Ÿปโ€โ™€๏ธ ๅ…่ดฃๅฃฐๆ˜Ž ็”ฑไบŽไผ ๆ’ญใ€ๅˆฉ็”จSunflower_get_Passwordๅทฅๅ…ทๆไพ›็š„ๅŠŸ่ƒฝ่€Œ้€ ๆˆ็š„ไปปไฝ•็›ดๆŽฅๆˆ–่€…้—ดๆŽฅ็š„ๅŽๆžœๅŠๆŸๅคฑ๏ผŒๅ‡็”ฑไฝฟ็”จ่€…ๆœฌไบบ่ดŸ่ดฃ๏ผŒๆœฌไบบไธไธบๆญคๆ‰ฟๆ‹…ไปปไฝ•่ดฃไปปใ€‚ ๅฎ‰่ฃ…็Žฏๅขƒ ๆœฌๅทฅๅ…ทไฝฟ็”จPython

635 Dec 20, 2022
WebScan is a web vulnerability Scanning tool, which scans sites for SQL injection and XSS vulnerabilities

WebScan is a web vulnerability Scanning tool, which scans sites for SQL injection and XSS vulnerabilities Which is a great tool for web pentesters. Coded in python3, CLI. WebScan is capable of scanni

AnonyminHack5 12 Dec 02, 2022
๐™พ๐š™๐šŽ๐š— ๐š‚๐š˜๐šž๐š›๐šŒ๐šŽ ๐š‚๐šŒ๐š›๐š’๐š™๐š - ๐™ฝ๐š˜ ๐™ฒ๐š˜๐š™๐šข๐š›๐š’๐š๐š‘๐š - ๐šƒ๐šŽ๐šŠ๐š– ๐š†๐š˜๐š›๐š” - ๐š‚๐š’๐š–๐š™๐š•๐šŽ ๐™ฟ๐šข๐š๐š‘๐š˜๐š— ๐™ฟ๐š›๐š˜๐š“๐šŽ๐šŒ๐š - ๐™ฒ๐š›๐šŽ๐šŠ๐š๐šŽ๐š ๐™ฑ๐šข : ๐™ฐ๐š•๐š• ๐šƒ๐šŽ๐šŠ๐š– - ๐™ฒ๐š˜๐š™๐šข๐™ฟ๐šŠ๐šœ๐š ๐™ฒ๐šŠ๐š— ๐™ฝ๐š˜๐š ๐™ผ๐šŠ๐š”๐šŽ ๐šˆ๐š˜๐šž ๐š๐šŽ๐šŠ๐š• ๐™ฟ๐š›๐š˜๐š๐š›๐šŠ๐š–๐š–๐šŽ๐š›

๐™พ๐š™๐šŽ๐š— ๐š‚๐š˜๐šž๐š›๐šŒ๐šŽ ๐š‚๐šŒ๐š›๐š’๐š™๐š - ๐™ฝ๐š˜ ๐™ฒ๐š˜๐š™๐šข๐š›๐š’๐š๐š‘๐š - ๐šƒ๐šŽ๐šŠ๐š– ๐š†๐š˜๐š›๐š” - ๐š‚๐š’๐š–๐š™๐š•๐šŽ ๐™ฟ๐šข๐š๐š‘๐š˜๐š— ๐™ฟ๐š›๐š˜๐š“๐šŽ๐šŒ๐š - ๐™ฒ๐š›๐šŽ๐šŠ๐š๐šŽ๐š ๐™ฑ๐šข : ๐™ฐ๐š•๐š• ๐šƒ๐šŽ๐šŠ๐š– - ๐™ฒ๐š˜๐š™๐šข๐™ฟ๐šŠ๐šœ๐š ๐™ฒ๐šŠ๐š— ๐™ฝ๐š˜๐š ๐™ผ๐šŠ๐š”๐šŽ ๐šˆ๐š˜๐šž ๐š๐šŽ๐šŠ๐š• ๐™ฟ๐š›๐š˜๐š๐š›๐šŠ๐š–๐š–๐šŽ๐š›

CodeX-ID 2 Oct 27, 2022
ADExplorerSnapshot.py is an AD Explorer snapshot ingestor for BloodHound.

ADExplorerSnapshot.py ADExplorerSnapshot.py is an AD Explorer snapshot ingestor for BloodHound. AD Explorer allows you to connect to a DC and browse L

576 Dec 23, 2022
SecurAID securely connects aid organizations directly with individuals in dangerous situations to allow them to discreetly and effectively get the assistance they need.

SecurAID securely connects aid organizations directly with individuals in dangerous situations to allow them to discreetly and effec

Ty K 2 Mar 23, 2022
Signatures and IoCs from public Volexity blog posts.

threat-intel This repository contains IoCs related to Volexity public threat intelligence blog posts. They are organised by year, and within each year

Volexity 130 Dec 29, 2022
Python exploit code for CVE-2021-4034 (pwnkit)

Python3 code to exploit CVE-2021-4034 (PWNKIT). This was an exercise in "can I make this work in Python?", and not meant as a robust exploit. It Works

Joe Ammond 92 Dec 29, 2022
Ensure secure infrastructure and consistency with the firewall rules

Python Port Scanner This script tries to check if it's possible to make a connection with the specific endpoint port. This is very useful to ensure se

Allan Avelar 7 Feb 26, 2022
A fast tool to scan prototype pollution vulnerability

proto A fast tool to scan prototype pollution vulnerability Syntax python3 proto.py -l alive.txt Requirements Selenium Google Chrome Webdriver Note :

Muhammed Mahdi 4 Aug 31, 2021