bcoles
04aa05faa2
ms01_026_dbldecode: Use HttpClient; remove meterpreter code; fix stager
2022-07-03 18:22:55 +10:00
Spencer McIntyre
a96bc36d9c
Update the docs with the Windows target
2022-06-15 17:24:44 -04:00
bwatters
3875db78ae
Land #16644 , Add Exploit for CVE-2022-26134 (Confluence RCE)
...
Merge branch 'land-16644' into upstream-master
2022-06-07 16:00:37 -05:00
Spencer McIntyre
1a06f69f95
Works through v7.18 now too
2022-06-06 22:03:21 -04:00
Spencer McIntyre
2c0e034a18
Fix a couple of typos
2022-06-06 18:14:05 -04:00
bwatters
c751ef46c9
Land #16635 , Add 0-day MSWord RCE #Follina CVE-2022-30190
...
Merge branch 'land-16635' into upstream-master
2022-06-06 14:41:31 -05:00
Spencer McIntyre
1aec2e8649
Note version in the docs
2022-06-03 18:29:28 -04:00
Spencer McIntyre
600fba7fa1
Add module docs
2022-06-03 17:26:15 -04:00
Christophe De La Fuente
474116d413
Land #16611 , DotCMS File Upload to RCE Module (CVE-2022-26352)
2022-06-02 15:30:10 +02:00
RAMELLA Sébastien
3ab06461af
fix. second review
2022-06-02 00:58:20 +04:00
RAMELLA Sébastien
dd1814903c
fix. SRVHOST default value
2022-06-02 00:07:15 +04:00
RAMELLA Sébastien
8c19a02835
fix. first review
2022-06-01 20:15:08 +04:00
Jack Heysel
bea4207c62
Land PR #16607 - MyBB RCE Module (CVE-2022-24734)
...
This exploit module leverages an improper input validation
vulnerability in MyBB prior to 1.8.30 to execute arbitrary
code in the context of the user running the application.
2022-05-31 11:59:53 -04:00
RAMELLA Sébastien
7f89e92da3
add more informations about
2022-05-31 00:12:30 +04:00
Jack Heysel
2c02a607ee
Responded to PR feedback
2022-05-30 14:46:54 -04:00
RAMELLA Sébastien
97921b4ed9
fix chmod 644
2022-05-30 22:11:35 +04:00
RAMELLA Sébastien
dfc226cf5f
add. Supposed 0day MSWord RCE
2022-05-30 21:23:18 +04:00
Christophe De La Fuente
b996f5ee49
Fixes from code review
2022-05-30 16:24:18 +02:00
Jack Heysel
9d9d81a855
Docs update
2022-05-24 10:16:36 -04:00
Christophe De La Fuente
bac9be956f
Add documentation
2022-05-23 17:27:42 +02:00
Jack Heysel
3afb9b2ffe
dotCMS file upload to RCE module
2022-05-20 15:57:22 -04:00
Spencer McIntyre
02e7a65b93
Just move the auxiliary module into an exploit
2022-05-16 17:44:31 -04:00
Jake Baines
39567281bf
Revised setup guidance
2022-05-13 13:41:05 -07:00
Grant Willcox
2eb31cf765
Add in edits from review
2022-05-13 15:32:12 -05:00
Jake Baines
da133a34c8
Updated affected
2022-05-12 03:22:02 -07:00
Jake Baines
617b4ae044
Initial commit of Zyxel unauth command injection (CVE=2022-30525)
2022-05-12 01:43:59 -07:00
Grant Willcox
6354d7a055
Redo explanation of exploit in documentation to appropriately account for various nuances. Also update exploit title and description accordingly.
2022-05-11 16:43:36 -05:00
Heyder Andrade
8a6dd7152e
Added tested versions reference
2022-05-11 16:43:12 -05:00
Heyder Andrade
77f60eb21e
Added module and documentation for f5 icontrol RCE (CVE-2022-1388)
2022-05-11 16:43:00 -05:00
Grant Willcox
1c934b87b4
Land #16169 , Add sploit for Cisco RV340 SSL VPN - CVE-2022-20699
2022-05-11 10:15:08 -05:00
Grant Willcox
68fdb103fe
Add in final touch ups to documentation to fix a typo or two for formatting. Also update exploit ranking since this exploit doesn't retrieve version information before exploiting and is not 100% reliable so Excellent ranking isn't appropriate
2022-05-11 09:39:47 -05:00
Grant Willcox
5a04f8253c
Land #16551 , Add docker documentation for tomcat mgr upload
2022-05-10 12:03:18 -05:00
Grant Willcox
6a7be290ff
Add in minor changes to improve overall formatting and presentation of documentation
2022-05-10 12:02:45 -05:00
adfoster-r7
ff410b23a0
Add documentation for tomcat mgr upload
2022-05-10 17:01:40 +01:00
bwatters
92715c883f
Land #16423 , Add module for exploit CVE-2022-22965
...
Merge branch 'land-16423' into upstream-master
2022-05-10 08:44:06 -05:00
bwatters
43f2b4dcf9
Quick update to the vulhub guidance
2022-05-10 08:42:02 -05:00
dwelch-r7
1f4ee19c05
Expose options for logging to a file in mettle
2022-05-06 14:36:55 +01:00
Spencer McIntyre
7646bf9e0a
Update the module docs
2022-05-05 11:26:37 -04:00
space-r7
e2cefe0750
Land #16514 , add ZoneMinder exploit module
2022-05-04 17:37:08 -05:00
space-r7
dd0b124e84
fix typo in docs, check some responses
2022-05-04 17:28:37 -05:00
William Vu
6532365dc8
Deregister VHOST
2022-05-03 11:52:50 -05:00
William Vu
8c0cd40a19
Fix VMware Workspace ONE Access CVE-2022-22954
2022-05-03 10:39:58 -05:00
dwelch-r7
a76600f4a9
Land #16462 , add support for armle/aarch64 architectures
2022-05-03 15:48:50 +01:00
krastanoel
0f5e31d593
Apply suggestions from code review
...
Update documentation common default options
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com >
2022-05-03 15:43:38 +07:00
William Vu
4ea72bb7a7
Add log IOC
2022-05-03 02:38:29 -05:00
William Vu
184b1b1e76
Add module doc
2022-05-02 20:41:01 -05:00
Spencer McIntyre
c994f8e933
Land #16507 , Add WSO2 file upload RCE module
2022-04-29 09:58:55 -04:00
krastanoel
bb8c130740
Fix docs typo
2022-04-28 21:57:18 +07:00
krastanoel
eba436dd99
Add Zoneminder Language rce module docs
2022-04-28 21:01:00 +07:00
vleminator
f8887dbf1c
Reflect changes in the console output
2022-04-28 00:22:44 +02:00