William Vu
6326aa5dda
Clean up module and randomize username
2019-04-12 14:23:57 -05:00
William Vu
2ebee1226f
Land #11613 , Cisco RV130 stack BOF exploit
2019-04-12 14:06:51 -05:00
Quentin Kaiser
5e189196de
Target consolidation.
2019-04-12 10:58:56 +02:00
Quentin Kaiser
dfb1ebb2e2
Remove Stance value as it is already defined by core/exploit/cmdstager/http.
2019-04-12 10:57:50 +02:00
William Vu
d72672feed
Land #11672 , Zimbra XXE and SSRF exploit
2019-04-10 09:58:45 -05:00
Quentin Kaiser
3517a4e237
Adapt ranking and mention potential stability issue.
2019-04-09 11:31:15 +02:00
todb-r7
9e3984ea51
Remove duplicate CVE for Mailcleaner module
...
See #11304
2019-04-02 12:51:09 -05:00
Jacob Robles
3d662bd962
Fix words because words...
2019-04-01 17:21:23 -05:00
Jacob Robles
69062bb220
Syntax fixes
2019-04-01 17:05:42 -05:00
Jacob Robles
c07b015734
File cleanup
2019-04-01 11:39:40 -05:00
Jacob Robles
51d1216953
Update module name
2019-04-01 07:48:26 -05:00
Jacob Robles
0873ba7ac1
Add Zimbra XXE to RCE module
2019-04-01 07:32:57 -05:00
Brent Cook
0a24266029
Land #11482 , RV320 Unauthenticated RCE
2019-03-28 17:53:05 -05:00
Quentin Kaiser
9baaedce4e
Indicate potential DoS in description. Define exploit stance explicitly.
2019-03-24 22:29:07 +01:00
Quentin Kaiser
5c048e7cd6
CISCO-SA not supported.
2019-03-24 22:20:31 +01:00
Quentin Kaiser
be73f56610
Only got researchers name, no email.
2019-03-24 17:50:31 +01:00
Quentin Kaiser
4451225da7
Add httpd service reloading.
2019-03-24 17:49:55 +01:00
bcoles
5e470a538d
return unless res
2019-03-23 19:38:14 +11:00
Brendan Coles
ccc8d9cdab
return unless res
2019-03-23 08:51:25 +00:00
Quentin Kaiser
5562af39d3
Use CmdStager instead of hardcoded wget command.
2019-03-22 20:10:29 +01:00
Quentin Kaiser
ef2c4310a4
Exploit for CVE-2019-1663 on Cisco RV130(W).
2019-03-22 17:34:12 +01:00
blightzero
9bb7f11897
Unregister SSLCert option since it is never used in thisHTTPServer module.
2019-03-20 14:21:40 +01:00
blightzero
1e00c28701
Checked the functionality of module. Added ability to connect via HTTPS.
2019-03-14 15:54:02 +01:00
William Vu
715409496e
Fix #11210 , imperva_securesphere_exec options
2019-03-05 22:01:24 -06:00
William Vu
4e31f53ca2
Fix required USERNAME and PASSWORD
...
Somehow I forgot to commit this? Strange.
2019-03-05 21:57:42 -06:00
William Vu
c48dec7331
Land #11210 , imperva_securesphere_exec exploit
2019-03-05 21:52:13 -06:00
William Vu
4e76eeceb7
Clean up module
2019-03-05 21:37:55 -06:00
blightzero
0551f3df3c
Refactored code to return early. Untested.
2019-03-05 17:55:34 +01:00
rsp3ar
b5587b926c
Add ForceExploit and fix code ident
2019-02-26 19:59:31 -08:00
blightzero
5f8f49ebcb
Removed all Warnings and Fixed Date Format.
2019-02-26 09:20:04 +01:00
blightzero
f64e517b73
Cisco RV32x RCE added reference IDs, some beautifications.
2019-02-25 15:51:14 +01:00
blightzero
de5a5ea805
Cisco RV32x RCE added reference IDs, some beautifications.
2019-02-25 15:51:14 +01:00
Benjamin
9d0b434f35
Initial commit Cisco RV320 and RV325 remote code execution
2019-02-25 15:51:05 +01:00
Wei Chen
18a4af1d1d
Land #11279 , improve imap_open exploit to be more robust
2019-02-08 18:28:08 -06:00
Tod Beardsley
daa3076d42
Add CVE-2018-1000999 to MailCleaner module
...
See PR #11148
This adds the new CVE assigned by DWF for this vulnerability.
Note that [CVE-2018-10933](https://www.cvedetails.com/cve/CVE-2018-10933/ )
describes a vulnerability in libssh, but this one describes the issue as
it pertains to MailCleaner specifically.
2019-01-23 09:27:12 -06:00
h00die
f47060870a
horde imp h3 imap_open
2019-01-18 19:43:45 -05:00
h00die
2585e4b708
horde imp h3 imap_open
2019-01-18 19:38:30 -05:00
h00die
5d49f04948
not working horde imp imap_open
2019-01-17 19:55:42 -05:00
rsp3ar
2577160449
update print_error, add PrependFork and adjust timeout
2019-01-16 23:20:06 -08:00
Wei Chen
47f8738f74
Add Imran Rashid to CVE-2018-11770 credit
2019-01-14 15:28:08 -06:00
Wei Chen
52ff0a8b75
Update exploits/linux/http/spark_unauth_rce as CVE-2018-11770
2019-01-14 15:10:29 -06:00
Brendan Coles
24f807490f
revisionism
2019-01-10 19:19:14 +00:00
rsp3ar
71aa4c8d9e
Adding respond code/body check for successful command execution
2019-01-10 00:01:19 -08:00
rsp3ar
3aabeee959
Update SSL, timeout and uid regex
2019-01-09 23:20:37 -08:00
Brendan Coles
5a956bb27b
Apply suggestions from code review
...
Co-Authored-By: rsp3ar <rsp3ar@users.noreply.github.com >
2019-01-09 21:07:01 -08:00
h00die
799a79b715
ueb priv esc suggestion
2019-01-09 20:28:53 -05:00
rsp3ar
24de5d6ee3
Update to use CmdStager
2019-01-08 20:07:35 -08:00
Jacob Robles
a0acfa79d7
Target payloads
2019-01-08 13:27:26 -06:00
rsp3ar
bab651e94d
Add Imperva SecureSphere module
2019-01-07 22:18:04 -08:00
Mehmet İnce
4e8ad22a7a
Adding CVE number
2018-12-26 13:15:36 +03:00