Jack Heysel
|
bf7884b2dc
|
Removed need to auth twice when AutoCheck enabled
|
2023-02-22 12:28:28 -05:00 |
|
Imran E. Dawoodjee
|
2b5b17916f
|
Update docs, improved robustness of module+lib
|
2023-02-22 22:41:14 +08:00 |
|
Jack Heysel
|
0c8df1a67b
|
Updated docs and module suggetsions
|
2023-02-22 00:33:40 -05:00 |
|
jheysel-r7
|
42146fc4ec
|
Update modules/exploits/linux/http/froxlor_log_path_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2023-02-21 23:02:49 -05:00 |
|
jheysel-r7
|
80cec400bf
|
Update modules/exploits/linux/http/froxlor_log_path_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2023-02-21 22:59:23 -05:00 |
|
jheysel-r7
|
fc5f4983f6
|
Update modules/exploits/linux/http/froxlor_log_path_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2023-02-21 22:58:49 -05:00 |
|
jheysel-r7
|
647418745f
|
Update modules/exploits/linux/http/froxlor_log_path_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2023-02-21 22:58:41 -05:00 |
|
Joshua Rogers
|
0f5f495108
|
Add default locations for the Jenkins home directory, and add an optional value that a user can suggest the home directory.
|
2023-02-22 03:56:54 +01:00 |
|
Jack Heysel
|
e625e2e474
|
Land #17652, module for pyload js2py exploit
This adds an exploit for CVE-2023-0297 which is unauthenticated
Javascript injection in pyLoads Click N Load service.
|
2023-02-21 16:27:04 -05:00 |
|
Spencer McIntyre
|
6dbf22a5e7
|
Automatically rebind on STATUS_PIPE_DISCONNECTED
|
2023-02-21 15:51:10 -05:00 |
|
Spencer McIntyre
|
fa3baa40e6
|
Add three new petitpotam methods
|
2023-02-21 14:38:52 -05:00 |
|
sfewer-r7
|
963b9a9952
|
Merge remote-tracking branch 'origin/CVE-2022-21587' into CVE-2022-21587
|
2023-02-21 18:02:10 +00:00 |
|
sfewer-r7
|
3854c30a11
|
more specific testing of the response after upload to ensure it contains the expected EBS response data. infer the relative path traversal depth from the path to the upload folder, thanks @gwillcox-r7
|
2023-02-21 18:00:17 +00:00 |
|
Imran E. Dawoodjee
|
6e9a7a9d07
|
Minor fixes
|
2023-02-20 23:45:59 +08:00 |
|
archcloudlabs
|
bf5919f461
|
finisehd msftidy/rubocop fixs
|
2023-02-19 19:49:39 -05:00 |
|
archcloudlabs
|
fc5a38e870
|
Simplifying the module
|
2023-02-19 19:49:39 -05:00 |
|
archcloudlabs
|
1f45b1e4b7
|
initial commit of disable_clamav module
|
2023-02-19 19:49:39 -05:00 |
|
ajmeese7
|
a2026182e1
|
feat: created module to exploit CVE-2019-16328
|
2023-02-19 16:03:05 -05:00 |
|
JBince
|
75fb5e883d
|
Exploit update based on feedback
|
2023-02-19 09:16:56 -06:00 |
|
Imran E. Dawoodjee
|
bdc435f5c8
|
Add login module for Softing Secure Integration Server
|
2023-02-19 22:25:22 +08:00 |
|
Grant Willcox
|
c713da368d
|
Add in a few fixes from the review
|
2023-02-17 14:52:57 -06:00 |
|
space-r7
|
871c9c57f3
|
add logic to retrieve email address
|
2023-02-17 14:13:29 -06:00 |
|
JBince
|
ce9933fc4c
|
Feedback changes + rubocop & msftidy changes
|
2023-02-17 08:16:49 -06:00 |
|
sfewer-r7
|
73e82274dd
|
changes as per @gwillcox-r7 review
|
2023-02-17 13:10:53 +00:00 |
|
space-r7
|
197124dd76
|
add Git usage, repository creation
|
2023-02-16 17:38:02 -06:00 |
|
JBince
|
a3a6ae9c4a
|
feedback fixes
|
2023-02-16 14:33:03 -06:00 |
|
Jonas Vestberg
|
c610949a5a
|
Move temp storage of reg hives to %TEMP%
|
2023-02-16 20:13:31 +01:00 |
|
Jack Heysel
|
44c393e2f1
|
Fixed netcat session cleanup
|
2023-02-16 13:14:24 -05:00 |
|
Jack Heysel
|
1c49b002d2
|
Changed get_csrf to use xpath
|
2023-02-16 10:47:04 -05:00 |
|
Jack Heysel
|
00d1637f3d
|
Changed check method to use xpath
|
2023-02-16 10:33:15 -05:00 |
|
Spencer McIntyre
|
ecd5ad29a7
|
Add module docs
|
2023-02-15 16:29:42 -05:00 |
|
Arnout Engelen
|
5d8b1dc4a6
|
Link Hadoop YARN exploit to documentation
This exploit scans for misconfigured installations, link to the documentation
that describes how to properly secure it.
|
2023-02-15 21:17:26 +01:00 |
|
Spencer McIntyre
|
557042c91c
|
Initial exploit is working
|
2023-02-15 14:18:25 -05:00 |
|
Spencer McIntyre
|
ac9d60ce9e
|
Land #17281, Added module for CVE-2022-2992
Added module for CVE-2022-2992 - Gitlab Remote Command Execution via Github import
|
2023-02-14 16:57:29 -05:00 |
|
space-r7
|
78ae5f49ce
|
add gitlab prefix back to methods
|
2023-02-14 15:26:01 -06:00 |
|
space-r7
|
304b90ecc8
|
split mixins between forms and v4 api used
|
2023-02-14 12:37:43 -06:00 |
|
Jack Heysel
|
8aed02de3d
|
Linting
|
2023-02-14 10:39:47 -05:00 |
|
Jack Heysel
|
ff159c8760
|
Updated TODO
|
2023-02-13 20:24:32 -05:00 |
|
Jack Heysel
|
ca0b1ffe05
|
Documentation fixes
|
2023-02-13 19:56:23 -05:00 |
|
Jack Heysel
|
2e195b2742
|
Initial commit Froxlor RCE
|
2023-02-13 19:39:18 -05:00 |
|
Grant Willcox
|
d012145726
|
Land #17599, Cisco RV LAN Exploit - CVE-2022-20705 and CVE-2022-20707
|
2023-02-13 17:50:06 -06:00 |
|
Stephen Wildow
|
96fecb6048
|
Modified BadChars and FailWith codes
|
2023-02-13 17:49:09 -05:00 |
|
JBince
|
9c3cfd8bdb
|
Added documentation, cleaned up functions, rubocop fixes
|
2023-02-13 15:19:45 -06:00 |
|
Grant Willcox
|
45e453d687
|
Fix up remaining review comments
|
2023-02-13 15:07:25 -06:00 |
|
Spencer McIntyre
|
c3fa924cfa
|
Remove the NGROK_URL option
|
2023-02-13 14:31:44 -05:00 |
|
Spencer McIntyre
|
210b7a3254
|
Use #get_json_document instead of JSON.parse
Also fix typos
|
2023-02-13 14:00:13 -05:00 |
|
space-r7
|
d6419ee4fb
|
add check method, login, main logic
|
2023-02-13 11:31:06 -06:00 |
|
JBince
|
2a386981bd
|
Updated Module & Payloads + Rubocop Fixes
|
2023-02-13 09:03:57 -06:00 |
|
JBince
|
f4c5e34a1b
|
Added improved functionality on both Windows and Unix installs
|
2023-02-12 14:42:22 -06:00 |
|
JBince
|
fcfc39296f
|
Added improved functionality on both Windows and Unix installs
|
2023-02-12 14:39:11 -06:00 |
|