Atlassian Confluence Server和Atlassian Data Center都是澳大利亚Atlassian公司的产品。Atlassian Confluence Server是一套专业的企业知识管理与协同软件,也可以用于构建企业WiKi。Atlassian Data Center是一套数据中心系统。 Atlassian Confluence Server和Atlassian Data Center中的downloadallattachments资源存在路径遍历漏洞,该漏洞源于网络系统或
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Atlassian | Confluence | 2.0.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Python script to exploit confluence path traversal vulnerability cve-2019-3398 | https://github.com/superevr/cve-2019-3398 | POC Details |
| 2 | None | https://github.com/132231g/CVE-2019-3398 | POC Details |
| 3 | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-3398.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet