h00die
|
65aae010ce
|
more libs for moodle and teacher priv esc to rce module
|
2021-09-04 13:31:11 -04:00 |
|
h00die
|
5ea2cf9e5a
|
moodle_admin_shell_upload working and minor other fixes
|
2021-08-29 16:59:44 -04:00 |
|
h00die
|
176c1f0751
|
moodle lib and module
|
2021-08-29 10:50:25 -04:00 |
|
h00die
|
a35be13958
|
moodle 3.8.0 tested
|
2021-08-28 08:10:28 -04:00 |
|
h00die
|
c0a8535764
|
moodle spellcheck rce
|
2021-08-27 19:51:52 -04:00 |
|
Tim W
|
6c0b90eabb
|
Land #15532, add module for CVE-2021-21300 and git mixins
|
2021-08-26 18:26:04 +01:00 |
|
Spencer McIntyre
|
674628e600
|
Land #15384, Improve Windows RDLL injection
|
2021-08-26 12:11:44 -04:00 |
|
Grant Willcox
|
5a80e9678c
|
Address Spencer's comments and remove changes that don't directly use the DLL injection library API change
|
2021-08-24 16:34:01 -05:00 |
|
William Vu
|
e480e868b9
|
Remove dead cisco_rv130_rmi_rce documentation
It is now cve_2019_1663_cisco_rmi_rce.
|
2021-08-20 05:06:00 -05:00 |
|
William Vu
|
31796c6236
|
Land #15561, ProxyShell exploit
|
2021-08-19 10:31:02 -05:00 |
|
wvu
|
bcf00a0d3a
|
Update exchange_proxyshell_rce.md
|
2021-08-18 14:38:56 -05:00 |
|
Spencer McIntyre
|
75e63992d6
|
Write an exploit for ProxyShell
|
2021-08-18 10:50:34 -04:00 |
|
William Vu
|
521ca14773
|
Add Lucee Administrator CVE-2021-21307 exploit
|
2021-08-16 10:09:34 -05:00 |
|
space-r7
|
c9bdd96c76
|
remove GIT_HOOK option
post-checkout is the only hook that will work
with this exploit, so no option is needed. Also update
the documentation to reflect that.
|
2021-08-12 10:18:13 -05:00 |
|
Shelby Pace
|
0fe761b838
|
modify options and add documentation
|
2021-08-12 10:18:12 -05:00 |
|
Spencer McIntyre
|
82cc8526d4
|
Land #15501, Add CVE-2019-11580 (Atlassian Crowd)
|
2021-08-12 09:38:31 -04:00 |
|
Grant Willcox
|
85ef49a79c
|
Land #15535, Update psexec module to use SMBSHARE option name for consistency
|
2021-08-11 17:41:38 -05:00 |
|
Grant Willcox
|
5fdf990f24
|
Land #15519, Lexmark Universal Print Driver Local Privilege Escalation
|
2021-08-11 15:03:53 -05:00 |
|
Grant Willcox
|
92327461d3
|
Add in driver installation instructions to documentation
|
2021-08-11 14:40:21 -05:00 |
|
Grant Willcox
|
7b25bd366f
|
Update documentation and fix a few typos so that it reflects latest changes
|
2021-08-11 12:25:36 -05:00 |
|
Jacob Baines
|
afa3d92774
|
Switched to upnp implementation
|
2021-08-10 18:17:18 -04:00 |
|
adfoster-r7
|
b9d2f30bbd
|
Update psexec module to use SMBSHARE option name for consistency
|
2021-08-10 13:17:57 +01:00 |
|
Grant Willcox
|
55404ff29f
|
Further fixes from review and further touch up edits
|
2021-08-09 14:23:05 -05:00 |
|
Grant Willcox
|
f8d838bba2
|
Fix first round of comments from the review process
|
2021-08-09 12:13:27 -05:00 |
|
Grant Willcox
|
838142362c
|
Apply first round of updates from review comments to improve explanations of the vulnerability and fix some minor issues
|
2021-08-09 09:59:09 -05:00 |
|
Jacob Baines
|
0e41a0e81e
|
Addressed all but one review items
|
2021-08-07 06:46:49 -04:00 |
|
Jacob Baines
|
8d699c0c4e
|
Addressed various review comments
|
2021-08-06 14:55:50 -04:00 |
|
Grant Willcox
|
ade653f0bf
|
Final fixup edits to change the timeout value to be an advanced option and also to use send_req_cgi
|
2021-08-05 13:10:24 -05:00 |
|
Jacob Baines
|
f851faf2e4
|
Initial commit for Canon driver exploit
|
2021-08-05 11:17:45 -04:00 |
|
Grant Willcox
|
00cfdc4f17
|
Use Faker to generate a fake app name, add in option to specify timeout to server, and also fix Alan's remaining review comments
|
2021-08-05 09:46:34 -05:00 |
|
Jacob Baines
|
e6c48db072
|
Initial version of CVE-2021-35449
|
2021-08-04 16:08:43 -04:00 |
|
Grant Willcox
|
0d7d5ab93f
|
Switch over to Rex::MIME::Message to use our built in mixins, and also fix last remaining review comments
|
2021-08-02 11:17:26 -05:00 |
|
Grant Willcox
|
27f70af1b3
|
Fix up some of the mistakes wvu pointed out
|
2021-07-30 15:28:10 -05:00 |
|
Grant Willcox
|
3427571887
|
Push up working CVE-2019-11580 exploit and associated documentation
|
2021-07-30 12:07:12 -05:00 |
|
space-r7
|
809081bc5f
|
Land #15279, add Pi-Hole lpe
|
2021-07-29 11:15:17 -05:00 |
|
space-r7
|
0561ae978f
|
fix typos, pihole version in docs
|
2021-07-29 11:13:58 -05:00 |
|
Shelby Pace
|
183caff15c
|
Land #15418, add modern events calendar rce
|
2021-07-26 09:45:05 -05:00 |
|
Shelby Pace
|
38ae82155e
|
modify info, fix spacing
|
2021-07-26 09:43:34 -05:00 |
|
Shelby Pace
|
9e95eb7be1
|
Land #15408, add Wordpress sp doc file upload
|
2021-07-23 12:36:29 -05:00 |
|
Grant Willcox
|
2fb379374f
|
Update documentation where possible for changed exploits
|
2021-07-23 12:34:12 -05:00 |
|
Shelby Pace
|
d207f994c0
|
modify doc description
randomize form data, formatting
|
2021-07-23 12:33:41 -05:00 |
|
Grant Willcox
|
fabc566402
|
Improve process.rb's execute_dll to now automatically detect the architecture of the target and of the DLL and then appropriately decide if it needs to launch a WoW64 process to inject into.
|
2021-07-23 12:33:41 -05:00 |
|
Grant Willcox
|
bc0439fc47
|
Improve the list of potential processes to spawn and inject into to be more believable
|
2021-07-23 12:33:16 -05:00 |
|
Hakyac
|
1a55cfc88c
|
Update documentation/modules/exploit/multi/http/wp_plugin_sp_project_document_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-07-23 10:12:10 +02:00 |
|
Hakyac
|
76a7233ee9
|
Update documentation/modules/exploit/multi/http/wp_plugin_sp_project_document_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-07-23 10:12:00 +02:00 |
|
Hakyac
|
cf9a5be774
|
Update documentation/modules/exploit/multi/http/wp_plugin_sp_project_document_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-07-23 10:11:49 +02:00 |
|
Hakyac
|
9eb8d521f8
|
Update documentation/modules/exploit/multi/http/wp_plugin_modern_events_calendar_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-07-23 10:08:19 +02:00 |
|
William Vu
|
af0092f290
|
Land #15400, Sage X3 modules
|
2021-07-20 20:36:48 -05:00 |
|
William Vu
|
b9a71449e5
|
Add module docs
|
2021-07-20 20:07:08 -05:00 |
|
Shelby Pace
|
79d49a6857
|
Land #15402, add Wordpress Backup Guard rce
|
2021-07-20 15:53:57 -05:00 |
|