Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-10148 PoC — SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API command

Source
Associated Vulnerability
Title: SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands (CVE-2020-10148)
Description:The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
Description
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
Readme
## 使用方法&免责声明

该脚本为SolarWinds Orion API 远程代码执行漏洞批量检测脚本(CVE-2020-10148)。

使用方法:`Python CVE-2020-10148.py urls.txt`

urls.txt 中每个url为一行,漏洞地址输出在vul.txt中

##### 影响版本:

SolarWinds Orion  2020.2.1 HF 2 及 2019.4 HF 6之前的版本受此漏洞影响。



工具仅用于安全人员安全测试,任何未授权检测造成的直接或者间接的后果及损失,均由使用者本人负责
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →