From 65d338d00e88ef370e7fa83dad213aff2d4db070 Mon Sep 17 00:00:00 2001 From: William Vu Date: Tue, 14 Apr 2020 13:58:50 -0500 Subject: [PATCH] Note tested version in module --- .../exploit/linux/http/nexus_repo_manager_el_injection.md | 2 +- modules/exploits/linux/http/nexus_repo_manager_el_injection.rb | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/documentation/modules/exploit/linux/http/nexus_repo_manager_el_injection.md b/documentation/modules/exploit/linux/http/nexus_repo_manager_el_injection.md index 981a3d3f6e..b7b634cfe2 100644 --- a/documentation/modules/exploit/linux/http/nexus_repo_manager_el_injection.md +++ b/documentation/modules/exploit/linux/http/nexus_repo_manager_el_injection.md @@ -4,7 +4,7 @@ This module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code -as the Nexus user. +as the Nexus user. Tested against 3.21.1-01. ### Setup diff --git a/modules/exploits/linux/http/nexus_repo_manager_el_injection.rb b/modules/exploits/linux/http/nexus_repo_manager_el_injection.rb index 9a5576be42..9b72508cf3 100644 --- a/modules/exploits/linux/http/nexus_repo_manager_el_injection.rb +++ b/modules/exploits/linux/http/nexus_repo_manager_el_injection.rb @@ -17,7 +17,7 @@ class MetasploitModule < Msf::Exploit::Remote 'Description' => %q{ This module exploits a Java Expression Language (EL) injection in Nexus Repository Manager versions up to and including 3.21.1 to execute code - as the Nexus user. + as the Nexus user. Tested against 3.21.1-01. }, 'Author' => [ 'Alvaro Muñoz', # Discovery