2015-07-22: 细节已通知厂商并且等待厂商处理中 2015-07-22: 厂商已经确认,细节仅向厂商公开 2015-08-01: 细节向核心白帽子及相关领域专家公开 2015-08-11: 细节向普通白帽子公开 2015-08-21: 细节向实习白帽子公开 2015-09-05: 细节向公众公开
RT
闪银solr未授权访问
http://www.wecash.net/solr/#/
参考: WooYun: 中青宝solr外网可访问(泄露数据库密码)
awt.toolkitsun.awt.X11.XToolkitcatalina.base/root/services/tomcat-solrcatalina.home/root/services/tomcat-solrcatalina.useNamingtruecommon.loader${catalina.base}/lib,${catalina.base}/lib/*.jar,${catalina.home}/lib,${catalina.home}/lib/*.jarfile.encodingUTF-8file.encoding.pkgsun.iofile.separator/java.awt.graphicsenvsun.awt.X11GraphicsEnvironmentjava.awt.printerjobsun.print.PSPrinterJobjava.class.path/root/services/tomcat-solr/bin/bootstrap.jar/root/services/tomcat-solr/bin/tomcat-juli.jarjava.class.version51.0java.endorsed.dirs/root/services/tomcat-solr/endorsedjava.ext.dirs/usr/local/java/jdk1.7.0_51/jre/lib/ext/usr/java/packages/lib/extjava.home/usr/local/java/jdk1.7.0_51/jrejava.io.tmpdir/root/services/tomcat-solr/tempjava.library.path/usr/java/packages/lib/amd64/usr/lib64/lib64/lib/usr/libjava.naming.factory.initialorg.apache.naming.java.javaURLContextFactoryjava.naming.factory.url.pkgsorg.apache.namingjava.runtime.nameJava(TM) SE Runtime Environmentjava.runtime.version1.7.0_51-b13java.specification.nameJava Platform API Specificationjava.specification.vendorOracle Corporationjava.specification.version1.7java.util.logging.config.file/root/services/tomcat-solr/conf/logging.propertiesjava.util.logging.managerorg.apache.juli.ClassLoaderLogManagerjava.vendorOracle Corporationjava.vendor.urlhttp://java.oracle.com/java.vendor.url.bughttp://bugreport.sun.com/bugreport/java.version1.7.0_51java.vm.infomixed modejava.vm.nameJava HotSpot(TM) 64-Bit Server VMjava.vm.specification.nameJava Virtual Machine Specificationjava.vm.specification.vendorOracle Corporationjava.vm.specification.version1.7java.vm.vendorOracle Corporationjava.vm.version24.51-b03line.separator\norg.apache.catalina.startup.ContextConfig.jarsToSkiporg.apache.catalina.startup.TldConfig.jarsToSkiptomcat7-websocket.jaros.archamd64os.nameLinuxos.version3.2.0-29-genericpackage.accesssun.,org.apache.catalina.,org.apache.coyote.,org.apache.tomcat.,org.apache.jasper.package.definitionsun.,java.,org.apache.catalina.,org.apache.coyote.,org.apache.tomcat.,org.apache.jasper.path.separator:server.loadershared.loadersun.arch.data.model64sun.boot.class.path/usr/local/java/jdk1.7.0_51/jre/lib/resources.jar/usr/local/java/jdk1.7.0_51/jre/lib/rt.jar/usr/local/java/jdk1.7.0_51/jre/lib/sunrsasign.jar/usr/local/java/jdk1.7.0_51/jre/lib/jsse.jar/usr/local/java/jdk1.7.0_51/jre/lib/jce.jar/usr/local/java/jdk1.7.0_51/jre/lib/charsets.jar/usr/local/java/jdk1.7.0_51/jre/lib/jfr.jar/usr/local/java/jdk1.7.0_51/jre/classessun.boot.library.path/usr/local/java/jdk1.7.0_51/jre/lib/amd64sun.cpu.endianlittlesun.cpu.isalistsun.io.unicode.encodingUnicodeLittlesun.java.commandorg.apache.catalina.startup.Bootstrap startsun.java.launcherSUN_STANDARDsun.jnu.encodingUTF-8sun.management.compilerHotSpot 64-Bit Tiered Compilerssun.os.patch.levelunknowntomcat.util.buf.StringCache.byte.enabledtruetomcat.util.scan.DefaultJarScanner.jarsToSkipbootstrap.jar,commons-daemon.jar,tomcat-juli.jar,annotations-api.jar,el-api.jar,jsp-api.jar,servlet-api.jar,websocket-api.jar,catalina.jar,catalina-ant.jar,catalina-ha.jar,catalina-tribes.jar,jasper.jar,jasper-el.jar,ecj-*.jar,tomcat-api.jar,tomcat-util.jar,tomcat-coyote.jar,tomcat-dbcp.jar,tomcat-jni.jar,tomcat-spdy.jar,tomcat-i18n-en.jar,tomcat-i18n-es.jar,tomcat-i18n-fr.jar,tomcat-i18n-ja.jar,tomcat-juli-adapters.jar,catalina-jmx-remote.jar,catalina-ws.jar,tomcat-jdbc.jar,tools.jar,commons-beanutils*.jar,commons-codec*.jar,commons-collections*.jar,commons-dbcp*.jar,commons-digester*.jar,commons-fileupload*.jar,commons-httpclient*.jar,commons-io*.jar,commons-lang*.jar,commons-logging*.jar,commons-math*.jar,commons-pool*.jar,jstl.jar,geronimo-spec-jaxrpc*.jar,wsdl4j*.jar,ant.jar,ant-junit*.jar,aspectj*.jar,jmx.jar,h2*.jar,hibernate*.jar,httpclient*.jar,jmx-tools.jar,jta*.jar,log4j.jar,log4j-1*.jar,mail*.jar,slf4j*.jar,xercesImpl.jar,xmlParserAPIs.jar,xml-apis.jar,junit.jar,junit-*.jar,hamcrest*.jar,org.hamcrest*.jar,ant-launcher.jar,cobertura-*.jar,asm-*.jar,dom4j-*.jar,icu4j-*.jar,jaxen-*.jar,jdom-*.jar,jetty-*.jar,oro-*.jar,servlet-api-*.jar,tagsoup-*.jar,xmlParserAPIs-*.jar,xom-*.jaruser.countryUSuser.dir/root/services/tomcat-solr/binuser.home/rootuser.languageenuser.namerootuser.timezoneAsia/Shanghai
我是来找礼物的!
危害等级:中
漏洞Rank:10
确认时间:2015-07-22 17:15
感谢对闪银的关注,我们会尽快修复漏洞。
暂无