inkognitobo
c15d513766
Add configurable JAVA_GADGET_CHAIN option to Shiro module
...
The gadget chain was previously hardcoded to CommonsCollections2.
Add a JAVA_GADGET_CHAIN OptEnum so operators can select the chain
that matches the target's classpath without modifying the module.
Default remains CommonsCollections2 to preserve existing behaviour.
2026-05-05 17:55:20 +02:00
Spencer McIntyre
0c81638fff
Fix ARMLE exec and add to Copy Fail
2026-04-30 20:03:04 -04:00
Brendan
dc97d1e97e
Merge pull request #21395 from zeroSteiner/feat/cve-2026-31431
...
Add exploit for CVE-2026-31431 (Copy Fail)
2026-04-30 17:19:08 -05:00
Spencer McIntyre
66995d3987
Only allow x64 and AARCH64 for now
2026-04-30 17:51:30 -04:00
Spencer McIntyre
cdcdb5fe88
Normalize reported ARMLE architectures from Meterpreter
2026-04-30 17:09:33 -04:00
Spencer McIntyre
0e02f10078
Add support for more architectures
2026-04-30 17:09:32 -04:00
Spencer McIntyre
e14ce079bb
Appease rubocop
2026-04-30 15:18:18 -04:00
Spencer McIntyre
22a9dc4522
Add docs
2026-04-30 14:54:09 -04:00
Spencer McIntyre
55f9216698
Finish the exploit check and cleanup methods
2026-04-30 14:39:46 -04:00
Spencer McIntyre
12e08fb451
Add an expanded check
2026-04-30 10:54:17 -04:00
adfoster-r7
3bee31ff5e
Update checkcodes and bug fixes
2026-04-30 15:42:10 +01:00
Spencer McIntyre
d0a205f776
Add the initial LPE exploit
2026-04-30 09:53:35 -04:00
cgranleese-r7
49ea1a3391
Merge pull request #21359 from adfoster-r7/improve-checkcode-messages-12
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-30 10:46:41 +01:00
cgranleese-r7
b3fbeced43
Merge pull request #21355 from adfoster-r7/improve-checkcode-messages-8
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-30 10:44:04 +01:00
cgranleese-r7
7b3aef8ede
Merge pull request #21353 from adfoster-r7/improve-checkcode-messages-6
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-30 10:43:21 +01:00
adfoster-r7
b59ced5057
Add human-readable descriptions to CheckCode returns in multi/http exploit modules (A-O)
2026-04-30 00:25:30 +01:00
adfoster-r7
0bf595c2ec
Add human-readable descriptions to CheckCode returns in unix/webapp exploit modules
2026-04-30 00:16:04 +01:00
adfoster-r7
1e3727ba87
Add human-readable descriptions to CheckCode returns in remaining multi exploit modules
2026-04-25 10:52:11 +01:00
adfoster-r7
e00515c172
Update logic for aux modules having called report_vuln already
2026-04-24 16:26:49 +01:00
cgranleese-r7
7c4f15a024
Merge pull request #21354 from adfoster-r7/improve-checkcode-messages-7
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-24 16:13:19 +01:00
adfoster-r7
7479078bf1
Merge pull request #21356 from adfoster-r7/improve-checkcode-messages-9
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-24 15:25:45 +01:00
adfoster-r7
b09686efaf
Merge pull request #21357 from adfoster-r7/improve-checkcode-messages-10
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-24 15:25:19 +01:00
adfoster-r7
b765db798e
Merge pull request #21358 from adfoster-r7/improve-checkcode-messages-11
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-24 15:25:00 +01:00
adfoster-r7
370c35c1e2
Add human-readable descriptions to CheckCode returns in windows/http exploit modules
2026-04-23 15:37:09 +01:00
Brendan
2289fc07ce
Merge pull request #21260 from Takahiro-Yoko/langflow_rce_cve_2026_27966
...
Add Langflow RCE module (CVE-2026-27966)
2026-04-23 09:12:12 -05:00
cgranleese-r7
1142d4e15d
Merge pull request #21351 from adfoster-r7/improve-checkcode-messages-4
...
Add human-readable descriptions to CheckCode returns modules
2026-04-23 12:54:31 +01:00
adfoster-r7
96a37da14a
Add human-readable descriptions to CheckCode returns in multi/http exploit modules (P-Z)
2026-04-23 12:26:32 +01:00
cgranleese-r7
9ad8b7ac32
Merge pull request #21360 from adfoster-r7/improve-checkcode-messages-13
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-23 11:55:46 +01:00
cgranleese-r7
591dbdd821
Merge pull request #21350 from adfoster-r7/improve-checkcode-messages-3
...
Add human-readable descriptions to CheckCode returns in modules
2026-04-23 11:33:27 +01:00
adfoster-r7
c38f6b4858
Update checkcodes and bug fixes
2026-04-23 10:20:53 +01:00
adfoster-r7
3e61396ec2
Add human-readable descriptions to CheckCode returns in unix, freebsd, osx, and other exploit modules
2026-04-23 10:02:22 +01:00
adfoster-r7
2ae936473e
Add human-readable descriptions to CheckCode returns in remaining windows exploit modules
2026-04-22 18:44:55 +01:00
adfoster-r7
45bc95a876
Add human-readable descriptions to CheckCode returns in windows/local exploit modules
2026-04-22 18:43:59 +01:00
adfoster-r7
05befe18b1
Add human-readable descriptions to CheckCode returns in linux/local exploit modules
2026-04-22 15:06:59 +01:00
adfoster-r7
2cbb3942b6
Add human-readable descriptions to CheckCode returns in linux/http exploit modules (A-M)
2026-04-22 13:08:59 +01:00
adfoster-r7
19d333df13
Add human-readable descriptions to CheckCode returns in linux/http exploit modules (N-Z)
2026-04-22 11:55:15 +01:00
Christophe De La Fuente
4c0f2c29bc
Merge pull request #21019 from g0tmi1k/phpmyadmin_config
2026-04-21 19:13:04 +02:00
Christophe De La Fuente
946d1a44b5
Fix Notes format (array)
2026-04-21 18:43:54 +02:00
Brendan
6b57b4c66f
Merge pull request #21256 from g0tmi1k/webdav
...
WebDAV improvements
2026-04-20 15:30:43 -05:00
Takah1ro
f54374eaff
Update exploit to improve stability
2026-04-18 12:56:53 +09:00
g0t mi1k
94b4f577e0
WebDAV: MR feedback
2026-04-17 22:19:26 +01:00
Takah1ro
a47234778c
Increase WfsDelay
2026-04-17 23:54:43 +09:00
Takah1ro
3cfbb90b0f
Fix bug
2026-04-17 07:31:25 +09:00
Takahiro Yokoyama
4c5ed36c88
Update modules/exploits/multi/http/langflow_rce_cve_2026_27966.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2026-04-17 07:10:53 +09:00
Takah1ro
4973d666ff
Relocate json to an external file
2026-04-16 21:57:07 +09:00
Takahiro Yokoyama
b917de89c3
Merge branch 'rapid7:master' into langflow_rce_cve_2026_27966
2026-04-16 20:58:02 +09:00
Brendan
c17c301e36
Merge pull request #21095 from LucasCsmt/multi/http/churchcrm_db_restore_rce
...
Adds exploit module for ChurchCRM authenticated RCE (CVE-2025-68109)
2026-04-15 14:22:56 -05:00
Diego Ledda
1d5eae0f5b
Merge pull request #21034 from Chocapikk/add-module-opendcim-sqli-rce
...
Add openDCIM install.php SQLi to RCE module
2026-04-14 16:04:13 -04:00
Diego Ledda
addcd69205
Merge pull request #20933 from madefourit/persis_pwrshell_profile
...
Windows Persistence: Powershell Profile
2026-04-14 15:43:06 -04:00
Diego Ledda
31a2de9562
Merge pull request #20839 from h00die/bits
...
New persistence module: Microsoft Bits
2026-04-14 15:42:55 -04:00