Web Hack List

Collected research

Apache Solr Injection Research

Apache Solr parameter injection: an application that pastes unencoded user input into its Solr query lets an attacker smuggle extra parameters such as shards, qt and stream.body, or Solr local parameters like an xmlparser query, and so reach the update and config endpoints. From there it chains to remote code execution, XXE, arbitrary file read and SSRF.

Record

Researcher
Michael Stepankin
Published by
GitHub
Format
Repository
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .