Sploitus

Exploit for Missing Authentication for Critical Function in Solarwinds Orion Platform

githubexploit Β· 2021-01-05

Exploit Code

README10 lines
## https://sploitus.com/exploit?id=F26F1877-9472-50A3-90E1-F1DE71E7AAB0
## Usage & Disclaimer

This script is a batch detection script for the remote code execution vulnerability of SolarWinds Orion API (CVE-2020-10148). Usage: `Python CVE-2020-10148.py urls.txt`.

Each URL is listed as a line in `urls.txt`; the vulnerability addresses are recorded in `vul.txt`.

##### Affected Versions:

Versions of SolarWinds Orion prior to 2020.2.1 HF 2 and 2019.4 HF 6 are affected by this vulnerability. This tool is only used for security personnel safety testing. Any direct or indirect consequences or losses caused by unauthorized detections are the responsibility of the user.