Tag
Atlassian Confluence CVE-2023-22515 Exploitation Attempt
2 rules 1 TTP 1 CVEDetection of CVE-2023-22515 exploitation attempts targeting Atlassian Confluence servers by sending crafted HTTP requests to specific vulnerable endpoints, potentially leading to unauthorized access and privilege escalation.
Confluence Pre-Auth RCE via OGNL Injection (CVE-2023-22527)
2 rules 1 TTP 1 CVEAttackers are exploiting CVE-2023-22527, a critical remote code execution vulnerability in Atlassian Confluence Server and Data Center, by sending crafted POST requests to a specific endpoint to inject and execute arbitrary OGNL expressions, potentially leading to complete system compromise.
Metasploit Exploitation via Malicious Confluence Plugin
2 rules 3 TTPsA Metasploit module exploits Atlassian Confluence servers by deploying a malicious Java plugin that downloads Meterpreter, granting the attacker full control over the compromised system.
Confluence Unauthenticated Remote Code Execution (CVE-2022-26134)
2 rules 4 TTPs 1 CVE 2 IOCsExploitation of CVE-2022-26134, an unauthenticated remote code execution vulnerability in Atlassian Confluence, allows attackers to execute arbitrary code on vulnerable servers, potentially leading to complete system compromise.