Anemone95 / anemone95.github.io

http://anemone.top/
2 stars 1 forks source link

Solr Velocity模板注入漏洞分析 | Anemone's Blog #73

Open Anemone95 opened 4 years ago

Anemone95 commented 4 years ago

https://anemone.top/vulnresearch-Solr_Velocity_injection/

环境搭建下载受影响版本的solr,这里依然选择v8.1.0,这里注意除了添加solr的jar还需要添加velocity的(源码的化可以让IDEA从maven上下源码):同样的方法启动项目1234anemone@ANEMONE-ASUS:/mnt/d/Store/document/all_my_work/solr/solr-8.1.0$ cd server/ #一定要在server下运行anemon