Matthew Dunn
|
b042e71b2a
|
Make Module work for both target url parameters
|
2023-02-07 14:18:04 -06:00 |
|
Matthew Dunn
|
b606d1ff6b
|
Add Documentation for Module
Fix CVE format
Add Documentation
|
2023-02-07 14:18:04 -06:00 |
|
Matthew Dunn
|
5846d95b25
|
Create nagios_xi_configwizards_authenticated_rce.rb
Add initial module
|
2023-02-07 14:18:03 -06:00 |
|
Stephen Wildow
|
475813eb33
|
Properly labing ZDI vulnerability
|
2023-02-05 21:48:48 -05:00 |
|
Stephen Wildow
|
59332da8ce
|
Randomized hard coded strings, modified cmd string, and updated references
|
2023-02-05 21:42:57 -05:00 |
|
Stephen Wildow
|
ac9caa8894
|
Removed unnecessary CVE listing
|
2023-02-05 14:32:04 -05:00 |
|
Stephen Wildow
|
7cff3cc2b0
|
Updated to include vulnerable versions of software
|
2023-02-05 13:20:52 -05:00 |
|
Stephen Wildow
|
4b3125d14b
|
Add module to exploit Cisco RV34x Small Business Routers
|
2023-02-05 10:15:16 -05:00 |
|
adfoster-r7
|
bbf17c167c
|
Land #17511, add exploit for CVE-2022-44877 command injection in CentOS Control Web Panel
|
2023-01-31 14:05:19 +00:00 |
|
Spencer McIntyre
|
f81195d0cc
|
Fix a typo
|
2023-01-25 13:45:18 -05:00 |
|
space-r7
|
153af9fb68
|
Land #17407, add Cacti unauth command injection
|
2023-01-23 13:06:46 -06:00 |
|
space-r7
|
58cd5bb003
|
specify command stager flavors
|
2023-01-23 11:53:19 -06:00 |
|
Spencer McIntyre
|
6fe0933c1e
|
Add exploit for CVE-2022-44877
|
2023-01-20 09:04:24 -05:00 |
|
Grant Willcox
|
7e23c34e6c
|
Apply fixes per code review
|
2023-01-17 12:44:22 -06:00 |
|
h00die-gr3y
|
541dab9365
|
simplified messaging
|
2023-01-17 12:44:20 -06:00 |
|
h00die-gr3y
|
77687bff3f
|
init module
|
2023-01-17 12:44:20 -06:00 |
|
ErikWynter
|
8472efed02
|
fix typos, add reference, don't use methods to wrap datastore options
|
2023-01-13 14:53:29 +02:00 |
|
Grant Willcox
|
f39973de86
|
Fix up missing option in documentation and also add some additional validation on server response.
|
2023-01-04 17:02:05 -06:00 |
|
h00die-gr3y
|
11b95b2094
|
added additional response check
|
2023-01-04 17:02:04 -06:00 |
|
h00die-gr3y
|
c7b59b4815
|
updates based on gwillcox-r7 review comments
|
2023-01-04 17:02:04 -06:00 |
|
h00die-gr3y
|
f9ecaa92ae
|
updated references section
|
2023-01-04 17:02:03 -06:00 |
|
h00die-gr3y
|
4db15346e1
|
init commit module
|
2023-01-04 17:01:58 -06:00 |
|
Christophe De La Fuente
|
20d70799a7
|
Land #17298, Add opentsdb_yrange_cmd_injection module and docs
|
2022-12-23 13:38:58 +01:00 |
|
Christophe De La Fuente
|
83b11a69a8
|
Make rubocop happy
|
2022-12-23 13:38:16 +01:00 |
|
ErikWynter
|
7fa557805e
|
add final code review suggestions
|
2022-12-23 11:29:29 +02:00 |
|
ErikWynter
|
8f96746551
|
fix typo and add credit for discovery
|
2022-12-23 11:11:31 +02:00 |
|
ErikWynter
|
4c2dfe0279
|
add cacti_unauthenticated_cmd_injection
|
2022-12-22 17:55:45 +02:00 |
|
Christophe De La Fuente
|
e7e2849f6d
|
Land #17183, Zimbra fixes
|
2022-12-06 15:38:37 +01:00 |
|
Christophe De La Fuente
|
ddaf5a3f0d
|
Remove unecessary return statement
|
2022-12-06 15:07:28 +01:00 |
|
bcoles
|
431804ef15
|
Fix typos: Replace 'the the' with 'the'
|
2022-12-04 17:41:24 +11:00 |
|
ErikWynter
|
78dfaa12ef
|
add opentsdb_yrange_cmd_injection module and docs
|
2022-11-24 21:37:24 +02:00 |
|
Spencer McIntyre
|
6350daf2d8
|
Land #17273, F5 exploit module CVE-2022-41800
F5 exploit module CVE-2022-41800 (authenticated RCE in RPM code)
|
2022-11-23 17:57:18 -05:00 |
|
Ron Bowes
|
b7cf112d42
|
Fix an issue where the session handler would close too early on Zimbra modules
|
2022-11-23 13:09:47 -08:00 |
|
Ron Bowes
|
ffbf8b303a
|
Change a 'return 0' to 'fail_with', per Christophe's request
|
2022-11-23 12:51:51 -08:00 |
|
Ron Bowes
|
28a68ede8c
|
Merge branch 'master' into zimbra-fixes
|
2022-11-23 12:50:56 -08:00 |
|
Ron Bowes
|
cbb50ed902
|
Remove non-functioning Arch'es
|
2022-11-23 10:42:07 -08:00 |
|
space-r7
|
8b30ff3dce
|
remove CmdStager inclusion
|
2022-11-18 16:18:25 -06:00 |
|
Ron Bowes
|
7ebf84c66b
|
Add URLs
|
2022-11-16 12:20:37 -08:00 |
|
Ron Bowes
|
20e6c1b55e
|
Add URLs
|
2022-11-16 12:19:16 -08:00 |
|
Ron Bowes
|
d0e109b842
|
Check in exploit module for CVE-2022-41800
|
2022-11-16 12:04:18 -08:00 |
|
Ron Bowes
|
99e661cfcf
|
Check in exploit script for CVE-2022-41622 (CSRF into SOAP)
|
2022-11-16 11:58:15 -08:00 |
|
h00die-gr3y
|
70669f3fea
|
addressed code improvement suggestions
|
2022-11-12 10:21:43 +00:00 |
|
H00die.Gr3y
|
72080910e7
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com>
|
2022-11-12 09:22:06 +01:00 |
|
H00die.Gr3y
|
85b4512292
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com>
|
2022-11-12 09:21:55 +01:00 |
|
H00die.Gr3y
|
5d314e5799
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com>
|
2022-11-12 09:21:42 +01:00 |
|
H00die.Gr3y
|
04d6a310af
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Spencer McIntyre <58950994+smcintyre-r7@users.noreply.github.com>
|
2022-11-12 09:16:46 +01:00 |
|
H00die.Gr3y
|
1ce8695401
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com>
|
2022-11-12 09:16:30 +01:00 |
|
H00die.Gr3y
|
e38138d69e
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com>
|
2022-11-12 09:16:17 +01:00 |
|
H00die.Gr3y
|
967388eba7
|
Update modules/exploits/linux/http/vmware_nsxmgr_xstream_rce_cve_2021_39144.rb
Agreed !
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com>
|
2022-11-12 09:15:42 +01:00 |
|
h00die-gr3y
|
da189041b4
|
randomized endpoint url
|
2022-11-07 08:16:54 +00:00 |
|