Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-3398 PoC — Atlassian Confluence Server和Atlassian Data Center 路径遍历漏洞

Source
Associated Vulnerability
Title:Atlassian Confluence Server和Atlassian Data Center 路径遍历漏洞 (CVE-2019-3398)
Description:Atlassian Confluence Server和Atlassian Data Center都是澳大利亚Atlassian公司的产品。Atlassian Confluence Server是一套专业的企业知识管理与协同软件,也可以用于构建企业WiKi。Atlassian Data Center是一套数据中心系统。 Atlassian Confluence Server和Atlassian Data Center中的downloadallattachments资源存在路径遍历漏洞,该漏洞源于网络系统或
Description
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center.
File Snapshot

id: CVE-2019-3398 info: name: Atlassian Confluence Download Attachments - Remote Code Execution ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.