Collected research
Compromising an unreachable Solr Serve
Agarri : Sécurité informatique offensive
Gregoire turns an XXE in a Java app into compromise of an unreachable Solr server: the XXE port-scans internally, finds Solr on 8983, then abuses Solr's XSLT response writer with a tr=../../ traversal to load an uploaded stylesheet and execute Java (CVE-2013-6397). The capture is the whole blog index, so it also carries Perl Storable, AMF XXE, Redis and XSLT-fuzzing posts.
Record
- Document
- Agarri : Sécurité informatique offensive
- Researcher
- Nicolas Grégoire
- Published by
- agarri.fr
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nicolas Grégoire, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .