GeoServer是一个用 Java 编写的开源软件服务器。允许用户共享和编辑地理空间数据。 GeoServer 2.21.4之前、2.22.2之前版本存在安全漏洞,该漏洞源于 ` ` 存在滥用 问题。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | CVE-2023-25157 - GeoServer SQL Injection - PoC | https://github.com/win3zz/CVE-2023-25157 | POC详情 |
| 2 | CVE-2023-25157 SQL injection vulnerability found in GeoServer | https://github.com/drfabiocastro/geoserver | POC详情 |
| 3 | None | https://github.com/0x2458bughunt/CVE-2023-25157 | POC详情 |
| 4 | GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158) | https://github.com/murataydemir/CVE-2023-25157-and-CVE-2023-25158 | POC详情 |
| 5 | A script, written in golang. POC for CVE-2023-25157 | https://github.com/7imbitz/CVE-2023-25157-checker | POC详情 |
| 6 | GeoServer OGC Filter SQL Injection Vulnerabilities | https://github.com/Rubikcuv5/CVE-2023-25157 | POC详情 |
| 7 | Geoserver SQL Injection Exploit | https://github.com/dr-cable-tv/Geoserver-CVE-2023-25157 | POC详情 |
| 8 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-25157.yaml | POC详情 |
| 9 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/GeoServer%20OGC%20Filter%20SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2023-25157.md | POC详情 |
| 10 | https://github.com/vulhub/vulhub/blob/master/geoserver/CVE-2023-25157/README.md | POC详情 | |
| 11 | None | https://github.com/custiya/geoserver-CVE-2023-25157 | POC详情 |
| 12 | CVE-2023-25157 exp | https://github.com/charis3306/CVE-2023-25157 | POC详情 |
| 13 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoTools FilterToSqlHelper.constructEquality writes the expected argument of the jsonArrayContains CQL function RAW into the SQL string while only escaping the JSON pointer. A single quote in the value parameter breaks out of the PostgreSQL jsonb_path_exists string literal, enabling unauthenticated SQL injection. When the PostGIS backend runs with superuser privileges, the injection escalates to operating system command execution through PostgreSQL COPY TO PROGRAM. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should enable the PostGIS DataStore preparedStatements setting and disable encode functions as a workaround. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/geoserver/geoserver-jsonarraycontains-sqli.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论