Sploitus

Exploit for Deserialization of Untrusted Data in Apache Solr

githubexploit Β· 2019-11-01

Exploit Code

README9 lines
## https://sploitus.com/exploit?id=F7B9CAF5-2381-5CE2-9434-D13B87CEBB2D
# Solr-RCE-CVE-2019-0192
Apache Solr remote code execution via dataImportHandler

### Target Solr version: 1.3 – 8.2
Requirements: DataImportHandler should be enabled, which is not by default. I have tested on version 6.2

### python 
python solr_RCE.py