Collected research
Apache Solr Injection Research
Apache Solr parameter injection: an application that pastes unencoded user input into its Solr query lets an attacker smuggle extra parameters such as shards, qt and stream.body, or Solr local parameters like an xmlparser query, and so reach the update and config endpoints. From there it chains to remote code execution, XXE, arbitrary file read and SSRF.
Record
- Researcher
- Michael Stepankin
- Published by
- GitHub
- Format
- Repository
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .