Eclipse BIRT是Eclipse基金会的一套为富客户端应用和Web应用提供报表和商业智能功能的开源软件。 Eclipse BIRT 存在代码问题漏洞,该漏洞源于在Eclipse BIRT版本4.8.0及更早的版本中,可以使用查询参数创建一个可以从远程(当前BIRT查看器dir)访问的JSP文件。攻击者可利用该漏洞将JSP代码注入到运行的实例中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Eclipse Foundation | Eclipse BIRT | unspecified ~ 4.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Eclipse BIRT versions 4.8.0 and earlier contain a JSP injection caused by query parameters, letting remote attackers create and access malicious JSP files in the viewer directory, exploit requires sending crafted query parameters. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-34427.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet