• XSS.stack #1 – первый литературный журнал от юзеров форума

Web JIRA LOGIN PORTAL EXPLOITS CVE - 2020-14181 / ETC

WujingKlaus

(L1) cache
Пользователь
Регистрация
05.05.2020
Сообщения
527
Реакции
33
Гарант сделки
2
LESS UPDATED JIRA LOGIN PORTALS ARE VULNERABLE TO MANY CVES' WHICH HELPS IN BUG BOUNTY / PENTESTING ..

FIRST USE DORKS ON TARGET TO FIND JIRA .

DORKS TO USE :
1.site:*..TLD inurl:jira login
2. inurl:company name intitle:jira login

THEN MANUALLY CHECK VERSION VIA VIEW SOURCE CODE : KEYWORD IN SOURCE => data-version
IF NOT UPDATED TO CURRENT USE THIS TOOL TO EXPLOIT CVES ON TARGET ,

Happy hunting / Pentesting
 
Sounds good. Assuming this applies to Jira instances that are self hosted, because otherwise Jira (main) would be patched by now

Ty for sharing
yes it applies to jira instances .. for big scopes (*) on bug hunts.
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх