solr-admin-query: Solr Admin Query Page

日期: 2025-09-01 | 影响软件: solr | POC: 已公开

漏洞描述

app="APACHE-Solr"

PoC代码[已公开]

id: solr-admin-query

info:
  name: Solr Admin Query Page
  author: dhiyaneshDK
  severity: high
  description: |
    app="APACHE-Solr"
  reference: 
    - https://www.exploit-db.com/ghdb/5856

rules:
    r0:
        request:
            method: GET
            path: /admin/
        expression: response.status == 200 && response.body.bcontains(b'<title>Solr admin page</title>')
    r1:
        request:
            method: GET
            path: /solr/admin/
        expression: response.status == 200 && response.body.bcontains(b'<title>Solr admin page</title>')
expression: r0() && r1()

相关漏洞推荐