1. 程式人生 > >elasitcsearch漏洞線上檢測工具

elasitcsearch漏洞線上檢測工具

ZoomEye釋出 ElasticSearch 遠端程式碼執行漏洞(CVE-2014-3120) 全球分佈:http://www.zoomeye.org/lab/es ElasticSearch 是一個廣泛使用的資料庫,在預設配置情況下,攻擊者可以傳送一個惡意請求讓伺服器執行 Java 程式碼,從而獲取資料庫敏感資訊甚至發起更深入的攻擊。線上漏洞檢測:http://tool.scanv.com/es.html

Elasticsearch is a powerful open source search and analytics engine. The vulnerability allows attackers read from or append to files on the system hosting ElasticSearch database, could lead to sensitive information disclosure or further attack. Not sured if your ES is vulnerable?

Inspect your server with SCANV now.