Christophe De La Fuente
847cd97927
Land #16925 , Fix a payload bug in unrar_cve_2022_30333
2022-08-23 12:59:37 +02:00
Ron Bowes
13d8c41f98
Clean up and better documentation
2022-08-22 11:46:50 -07:00
Spencer McIntyre
07fdc1f1ec
Land #16907 , ms10_092_schelevator: Cleanup
2022-08-22 11:53:02 -04:00
Grant Willcox
97bce45e69
Land #16915 , Add exploit for CVE-2022-23277 (Exchange RCE)
2022-08-19 11:11:46 -05:00
bcoles
666a3efcfd
ms10_092_schelevator: Cleanup
2022-08-19 15:19:28 +10:00
Christophe De La Fuente
d49b74d164
Land #16809 , Add exploit module for Advantech iView command injection - CVE-2022-2143
2022-08-18 17:19:14 +02:00
Spencer McIntyre
7c1dd17c86
Add a missing verison, fix typos
2022-08-17 17:36:31 -04:00
Spencer McIntyre
62ab42b797
Update vulnerable version numbers and docs
2022-08-17 08:55:46 -04:00
Jack Heysel
06f0fffc20
Land #16856 , Webmin package updates RCE module
...
This module exploits an arbitrary command injection
in Webmin versions prior to 1.997.
2022-08-09 16:13:19 -04:00
Spencer McIntyre
0e148d6ba4
Update and rename the module
2022-08-09 13:32:09 -04:00
Christophe De La Fuente
38b845f247
Fix from code review
...
- Documentation typos
- Adding ARM64 support
2022-08-09 15:09:25 +02:00
Ron Bowes
be25e1fc77
Add documentation
2022-08-05 13:55:05 -05:00
space-r7
0334beada2
Land #16758 , add ManageEngine ADAudit Plus exploit
2022-08-05 12:19:42 -05:00
space-r7
4202502992
make some prints vprints, add steps
2022-08-05 11:34:46 -05:00
Ron Bowes
7c21c57564
Merge branch 'master' into manageengine-adauditplus-cve-2022-28219
2022-08-04 14:07:50 -07:00
Christophe De La Fuente
9c6a198453
Land #16796 , Path traversal vulnerability in RARLAB UnRAR < 6.12 with Zimbra RCE module
2022-08-04 19:44:57 +02:00
bwatters
163d4d5b11
Land #16854 , Add CVE-2022-31660 VMware Workspace ONE Access LPE
...
Merge branch 'land-16854' into upstream-master
2022-08-03 16:50:12 -05:00
Christophe De La Fuente
449a7b71d5
Add module exploit and docs for the Webmin package updates RCE
2022-08-03 12:01:41 +02:00
Jack Heysel
82182f7815
Land #16852 , Zoho PMP XML-RPC Unauth RCE module
...
Add in exploit module for CVE-2022-35405 aka Zoho
Password Manager Pro XML-RPC Unauthenticated RCE
2022-08-02 17:18:28 -04:00
Spencer McIntyre
8ed4293e9c
Add module docs for CVE-2022-31660
2022-08-02 16:42:08 -04:00
Grant Willcox
ada3be8f7b
Update options section in documentation
2022-08-02 14:13:25 -05:00
Grant Willcox
f0e62de46a
Add CVE-2022-35405 docs and module
2022-08-02 11:57:56 -05:00
Jake Baines
b00cadfbeb
Initial commit of MobileIron Core Log4Shell exploitation (CVE-2021-44228)
2022-07-29 10:31:15 -07:00
Ron Bowes
4e4a1da4e4
Add module docs for the split-up unrar modules
2022-07-27 13:24:29 -07:00
Ron Bowes
b4b5f31c3d
Add documentation
2022-07-26 10:48:18 -07:00
Ron Bowes
860cd38bbb
Add documentation
2022-07-26 10:23:24 -07:00
Grant Willcox
74496c1a29
Add in updated scenario documentation
2022-07-25 14:14:52 -05:00
Grant Willcox
72b1dbfeee
Remove code that could cause check method to fail, fix up some documentation errors and add in scenario, and generally address some review comments
2022-07-25 13:05:04 -05:00
Nuri Çilengir
1094ce95c0
Update roxy_wi_exec.md
2022-07-25 17:14:02 +00:00
Nuri Çilengir
bdf8defe53
Apply suggestions from code review
2022-07-25 16:03:09 +00:00
Nuri Çilengir
bc0b27e1e2
Apply suggestions from code review
...
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com >
2022-07-22 12:58:46 +00:00
Nuri Çilengir
fc3b08fb8b
Apply suggestions from code review
...
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com >
2022-07-22 12:51:40 +00:00
Nuri Çilengir
420e67aca9
Apply suggestions from code review
...
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com >
2022-07-22 12:24:43 +00:00
Nuri Çilengir
628f5970b1
Apply suggestions from code review
...
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com >
2022-07-22 12:24:26 +00:00
space-r7
e1b0e871b3
add finished module and docs
2022-07-21 18:33:56 -05:00
Nuri Çilengir
135a25be4d
Tested and fixed problems
2022-07-21 11:42:18 +00:00
Grant Willcox
336a1feaf7
Fix up naming of module and documentation and fix most of the RuboCop and formatting errors
2022-07-19 15:44:52 -05:00
Nuri Çilengir
d2769ef82b
Add Roxy-WI exec
2022-07-19 21:08:45 +03:00
bwatters
e3e6afbaa3
Land #16753 , ms03_007_ntdll_webdav: Cleanup and add additional offsets
...
Merge branch 'land-16753' into upstream-master
2022-07-19 08:48:06 -05:00
Jack Heysel
2af8042bfa
Land #16761 , clean up ms01_023_printer
...
Adds additional offsets for various Windows 2000 targets.
Replaces raw socket TCP with HttpClient. This works fine in testing.
Fixes default payload, adds docs and notes.
2022-07-16 17:56:59 -04:00
Jack Heysel
77be219bc2
Land #16754 , add offsets to ms02_065
...
Adds additional offsets for various Windows 2000
Professional targets, adds docs, fixes default
payload and resolves rubocop violations.
2022-07-16 16:43:47 -04:00
Jack Heysel
819d1fa2dd
Land #16762 , Sourcegraph RCE module
...
This module exploits a vuln in the gitserver
component of sourcegraph that results in OS
command execution in the context of gitserver.
2022-07-13 10:09:06 -04:00
Jack Heysel
52fd45b7ab
Land #16744 Jboss EAP/AS RCE module
...
This module exploits a Java deserialization vulnerability
in JBOSS EAP/AS Remoting Unified Invoker interface for
versions 6.1.0 and prior.
2022-07-12 10:49:22 -04:00
Spencer McIntyre
63734832b2
Add sourcegraph RCE module docs
2022-07-08 17:27:27 -04:00
Spencer McIntyre
27ad62c964
Add a decent check method
2022-07-08 16:40:42 -04:00
bcoles
83bc954e9d
ms01_023_printer: cleanup; use HttpClient; add additional targets
2022-07-09 01:36:10 +10:00
Heyder Andrade
d6b6f47b09
change doc file
2022-07-08 02:36:18 +02:00
space-r7
f958b0a053
Land #16738 , correct CVE/lint for weblogic module
2022-07-07 18:08:13 -05:00
Jack Heysel
4da72a9b01
Land #16735 , Fix defaults for aerohive module
...
This change sets the MeterpreterTryToFork advanced
payload option to true by default for the Linux target
in the aerohive_netconfig_lfi_log_poison_rce module.
2022-07-07 16:21:56 -04:00
Erik Wynter
3ad42dd153
change option names to H3 for weblogic_deserialize_asyncresponseservice docs
...
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com >
2022-07-07 19:04:26 +03:00