msutovsky-r7
ffdfa07954
Land #20354 , adds module for ISPConfig code injection (CVE-2023-46818)
...
Add module for ISPConfig Code Injection (CVE-2023-46818)
2025-07-09 07:47:56 +02:00
msutovsky-r7
93f902fe27
Land #20364 , adds WingFTP unauthenticated RCE module
...
Add WingFTP unauthenticated RCE (CVE-2025-47812)
2025-07-07 13:12:10 +02:00
Martin Sutovsky
7d881567f2
Refactors code
2025-07-07 11:54:28 +02:00
Chocapikk
7629dd7518
DRY code, grab wingftp version in check method
2025-07-05 22:25:45 +02:00
Valentin Lobstein
6edbfb32ec
Update modules/exploits/multi/http/wingftp_null_byte_rce.rb
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2025-07-03 19:42:01 +02:00
happybear-21
1700b2eaaa
fixed: rubocop issues, changes resolved
2025-07-03 21:25:19 +05:30
Chocapikk
1944c699f8
Fix exploit/unix/http/maltrail_rce.rb
2025-07-03 14:07:14 +02:00
Valentin Lobstein
d79810a7e3
Update modules/exploits/multi/http/wingftp_null_byte_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-07-03 13:54:11 +02:00
Valentin Lobstein
d625ab5fbc
Update modules/exploits/multi/http/wingftp_null_byte_rce.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-07-03 13:54:01 +02:00
Valentin Lobstein
32f7754774
Update modules/exploits/multi/http/wingftp_null_byte_rce.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-07-02 14:42:34 +02:00
Chocapikk
5b268bd4b4
Fix documentation and typos
2025-07-01 22:50:01 +02:00
Chocapikk
f7a649c121
Remove php mixin and arch
2025-07-01 19:43:21 +02:00
Chocapikk
5d9eb58848
Remove useless mixin
2025-07-01 19:39:26 +02:00
Chocapikk
1a4a15e83b
Add WingFTP unauthenticated RCE (CVE-2025-47812)
2025-07-01 19:15:15 +02:00
happybear-21
03e943726a
resolved: changes updated methods
2025-07-01 21:33:41 +05:30
happybear-21
20134b5ced
resolved: changes
2025-07-01 15:37:10 +05:30
happybear-21
47f2ba2861
removed: unused imports, and functions, removed: falsey statements, resolved: changes
2025-06-30 20:34:17 +05:30
happybear-21
ff15b581ed
resolved: issues
2025-06-29 12:34:38 +05:30
happybear-21
e77abd9bbc
added: automatic admin_allow_langedit permission checking and enabling capability
2025-06-28 16:20:49 +05:30
Spencer McIntyre
50a2749f97
Merge pull request #20289 from cgranleese-r7/adds-mitre-attack-references
...
Adds support for MITRE ATT&CK References
2025-06-27 11:26:09 -04:00
msutovsky-r7
126bff18a1
Land #20346 , fixes payload encoding and substitutes for smaller base64 encoder
...
Use the smaller base64 encoder
2025-06-27 17:15:05 +02:00
happybear-21
93a8334699
fixed: build issue
2025-06-27 20:16:07 +05:30
happybear-21
840ae0f317
resolved: issues
2025-06-27 19:42:35 +05:30
Diego Ledda
a7b038b822
Merge pull request #20341 from msutovsky-r7/exploit/skyvern_ssti_rce
...
Adds module for Skyvern SSTI (CVE-2025-49619)
2025-06-27 14:14:40 +02:00
Martin Sutovsky
ee890a83ca
Adds BadChars
2025-06-27 11:03:08 +02:00
adfoster-r7
a0bb2d8c89
Merge pull request #20298 from bcoles/modules-SSL
...
Modules: Convert SSL default option to Boolean in several modules
2025-06-26 15:00:59 +01:00
happybear-21
016f4ea142
resolved: issues
2025-06-26 10:26:05 +05:30
happybear-21
d787444137
Add exploit module for ISPConfig language_edit.php PHP Code Injection (CVE-2023-46818)
...
- Adds modules/exploits/linux/http/ispconfig_lang_edit_php_code_injection.rb
- Adds documentation for the module in documentation/modules/exploit/linux/http/ispconfig_lang_edit_php_code_injection.md
- Module targets ISPConfig < 3.2.11p1 with admin_allow_langedit enabled
- References and implementation based on PoC and advisories at https://github.com/SyFi/CVE-2023-46818
2025-06-25 22:27:52 +05:30
cgranleese-r7
a6cdb6deb9
Adds support for MITRE ATT&CK References
2025-06-25 17:24:47 +01:00
cgranleese-r7
00c88caffb
Updates incorrect arch values in modules
2025-06-25 16:57:27 +01:00
cgranleese-r7
04a18fb3ca
Updates modules to remove non-printable chars
2025-06-25 14:19:56 +01:00
msutovsky-r7
fde78bf73f
Land #20324 , adds exploit for UNC path in .url files (CVE-2025-33053)
...
Adds exploit module for Internet Shortcut UNC path vulnerability (CVE-2025-33053)
2025-06-25 11:23:23 +02:00
Diego Ledda
6d843385ec
Merge pull request #20301 from msutovsky-r7/exploit/cve-2021-25094
...
Adds module for Tatsu WP plugin (CVE-2021-25094)
2025-06-25 10:58:22 +02:00
cgranleese-r7
40ca2b3b1b
Adds sentinel notes to modules that are missing stability, reliability or side effects
2025-06-25 09:32:01 +01:00
Spencer McIntyre
6334996e60
Use the smaller base64 encoder
2025-06-24 15:58:17 -04:00
Martin Sutovsky
13cd2d2e51
Minor code changes, updates documentation
2025-06-24 16:22:42 +02:00
DevBuiHieu
fa0d01f55c
Update modules/exploits/windows/fileformat/cve_2025_33053.rb
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-06-24 19:24:06 +07:00
cgranleese-r7
a454217bd4
Update info -d markdown
2025-06-24 11:21:49 +01:00
Martin Sutovsky
dd6bb2c8dc
Remove debug statements
2025-06-24 12:10:46 +02:00
Martin Sutovsky
3d9cc6063d
Adds SMB server to send payload
2025-06-24 12:10:19 +02:00
Martin Sutovsky
6aa24a0762
Adds researchers in author section, base for WebDAV server
2025-06-23 15:38:09 +02:00
cgranleese-r7
37388ca1be
Adds sentinel values to modules missing notes
2025-06-23 12:24:58 +01:00
adfoster-r7
be8864fe84
Merge pull request #20339 from bcoles/exploit-windows-fileformat-ms_visual_basic_vbp
...
exploit/windows/fileformat/ms_visual_basic_vbp: Add offsets, cleanup, document
2025-06-23 10:41:14 +01:00
bcoles
b483312eca
Modules: Convert SSL default option to Boolean in several modules
2025-06-23 19:38:36 +10:00
cgranleese-r7
ade9b54d94
Runs Style/TrailingCommaInArguments Rubocop against modules
2025-06-23 09:30:35 +01:00
Martin Sutovsky
ca142599e8
Module init
2025-06-23 10:27:27 +02:00
bcoles
e1dec29ef9
exploit/windows/browser/ms08_070_visual_studio_msmask: Cleanup and add documentation
2025-06-23 00:38:44 +10:00
bcoles
c0baf1888b
exploit/windows/fileformat/ms_visual_basic_vbp: Add offsets, cleanup, document
2025-06-23 00:11:54 +10:00
adfoster-r7
b8c375d087
Merge pull request #20337 from bcoles/exploit-linux-http-opentsdb_key_cmd_injection
...
opentsdb_key_cmd_injection: Set Arch to ARCH_CMD
2025-06-22 14:51:04 +01:00
bcoles
cede07596f
opentsdb_key_cmd_injection: Set Arch to ARCH_CMD
2025-06-22 12:39:04 +10:00