Zum Hauptinhalt springen
••
Linux Tipps & HardeningSecurity: Mehrere Probleme in lemonldap-ng (Fedora)(04.10.2026 um 09:18 Uhr)
•
Linux Tipps & HardeningSecurity: Denial of Service in nanosvg (Fedora)(04.10.2026 um 09:18 Uhr)
••
Sicherheitslücken (CVE)CVE-2025-29933 | AMD μProf up to 5.0 out-of-bounds write(04.10.2026 um 22:31 Uhr)
•••
Sichere ProgrammierungSafeSpeak -A Private English Practice Partner for My Shy Friend(04.10.2026 um 22:48 Uhr)
•
Sichere ProgrammierungBlazor Forms Hate Immutability(04.10.2026 um 22:48 Uhr)
•••
Linux Tipps & HardeningSecurity: Mehrere Probleme in lemonldap-ng (Fedora)(04.10.2026 um 09:18 Uhr)
•
Linux Tipps & HardeningSecurity: Denial of Service in nanosvg (Fedora)(04.10.2026 um 09:18 Uhr)
••
Sicherheitslücken (CVE)CVE-2025-29933 | AMD μProf up to 5.0 out-of-bounds write(04.10.2026 um 22:31 Uhr)
•••
Sichere ProgrammierungSafeSpeak -A Private English Practice Partner for My Shy Friend(04.10.2026 um 22:48 Uhr)
•
Sichere ProgrammierungBlazor Forms Hate Immutability(04.10.2026 um 22:48 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Splunk XSLT Upload Remote Code Execution

This Metasploit module exploits a remote code execution vulnerability in Splunk Enterprise. The affected versions include 9.0.x before 9.0.7 and 9.1.x before…

Beitrag
0
Seite
0
↗ Quelle (packetstormsecurity.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
This Metasploit module exploits a remote code execution vulnerability in Splunk Enterprise. The affected versions include 9.0.x before 9.0.7 and 9.1.x before 9.1.2. The exploitation process leverages a weakness in the XSLT transformation functionality of Splunk. Successful exploitation requires valid credentials, typically admin:changeme by default. The exploit involves uploading a malicious XSLT file to the target system. This file, when processed by the vulnerable Splunk server, leads to the execution of arbitrary code. The module then utilizes the runshellscript capability in Splunk to execute the payload, which can be tailored to establish a reverse shell. This provides the attacker with remote control over the compromised Splunk instance. The module is designed to work seamlessly, ensuring successful exploitation under the right conditions.
🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
2 belegte Techniken
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
T1071TA0011 · Command and Control
Application Layer Protocol (C2)
Mitigation: M1031 Network Intrusion Prevention & Egress Filtering
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
3 Knoten · 2 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Splunk XSLT Upload Remote Code Execution

Thematisch verwandte Begriffe: Splunk, XSLT, Upload, Remote · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag