Files
CVEs-PoC/2021/CVE-2021-26085.md
T
2024-08-05 18:41:32 +00:00

53 lines
2.4 KiB
Markdown

### [CVE-2021-26085](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26085)
![](https://img.shields.io/static/v1?label=Product&message=Confluence%20Data%20Center&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Confluence%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%207.4.10%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Pre-Authorization%20Arbitrary%20File%20Read&color=brighgreen)
### Description
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.
### POC
#### Reference
- http://packetstormsecurity.com/files/164401/Atlassian-Confluence-Server-7.5.1-Arbitrary-File-Read.html
#### Github
- https://github.com/0xStrygwyr/OSCP-Guide
- https://github.com/0xZipp0/OSCP
- https://github.com/0xsyr0/OSCP
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/ColdFusionX/CVE-2021-26085
- https://github.com/Loginsoft-LLC/Linux-Exploit-Detection
- https://github.com/Loginsoft-Research/Linux-Exploit-Detection
- https://github.com/Ly0nt4r/OSCP
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/SenukDias/OSCP_cheat
- https://github.com/SirElmard/ethical_hacking
- https://github.com/Threekiii/Awesome-POC
- https://github.com/d4n-sec/d4n-sec.github.io
- https://github.com/e-hakson/OSCP
- https://github.com/eljosep/OSCP-Guide
- https://github.com/emadshanab/Some-BugBounty-Tips-from-my-Twitter-feed
- https://github.com/enomothem/PenTestNote
- https://github.com/k0mi-tg/CVE-POC
- https://github.com/kgwanjala/oscp-cheatsheet
- https://github.com/manas3c/CVE-POC
- https://github.com/nitishbadole/oscp-note-3
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/oscpname/OSCP_cheat
- https://github.com/pen4uin/awesome-vulnerability-research
- https://github.com/pen4uin/vulnerability-research
- https://github.com/pen4uin/vulnerability-research-list
- https://github.com/revanmalang/OSCP
- https://github.com/txuswashere/OSCP
- https://github.com/whoforget/CVE-POC
- https://github.com/xhref/OSCP
- https://github.com/youwizard/CVE-POC
- https://github.com/zeroc00I/CVE-2021-26085
- https://github.com/zhibx/fscan-Intranet