Jack Heysel
|
a3a7454f74
|
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
|
2023-08-29 15:24:04 -04:00 |
|
Jack Heysel
|
b326832bcf
|
Renamed module, rubocop
|
2023-08-29 13:21:13 -04:00 |
|
Ege Balcı
|
44dd8439df
|
Add low version guard and token check
|
2023-08-29 17:43:21 +02:00 |
|
h00die
|
db9bf5f6cd
|
now down to 10 shells!
|
2023-08-28 17:42:35 -04:00 |
|
h00die
|
f467e0747a
|
review comments
|
2023-08-28 17:39:02 -04:00 |
|
h00die-gr3y
|
77a1bbef79
|
Second release module and documentation
|
2023-08-28 07:49:40 +00:00 |
|
Ege Balcı
|
eaeb2024d3
|
Merge branch 'master' into vmware_vrli_rce
Merge for ThriftMessageType
|
2023-08-26 22:42:25 +02:00 |
|
h00die
|
b529814563
|
fix sideeffects/reliability
|
2023-08-24 16:28:05 -04:00 |
|
h00die
|
5382eb22d1
|
kibana exploit
|
2023-08-24 16:08:08 -04:00 |
|
Christophe De La Fuente
|
a037d16b66
|
Land #18233, Chamilo unauthenticed RCE [CVE-2023-34960]
|
2023-08-24 11:49:40 +02:00 |
|
h00die-gr3y
|
3612030cee
|
first release of module
|
2023-08-23 22:07:58 +00:00 |
|
h00die-gr3y
|
f64b67968f
|
Final minor updates
|
2023-08-23 11:38:07 +00:00 |
|
H00die.Gr3y
|
1db284dcaa
|
Apply suggestions from code review
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com>
|
2023-08-22 18:46:25 +02:00 |
|
h00die
|
1bd14dd8f4
|
error handling for apache modules
|
2023-08-21 18:12:26 -04:00 |
|
h00die
|
a45792877a
|
lib and spec updates
|
2023-08-20 19:37:22 -04:00 |
|
h00die-gr3y
|
b6cf981378
|
Updates based on review comments
|
2023-08-19 08:18:50 +00:00 |
|
Ege Balcı
|
e0f545673c
|
Add files for cleanup, fix serve address, add retry_until_truthy
|
2023-08-18 23:25:49 +02:00 |
|
Ege Balcı
|
e97183e7bd
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:21:42 +00:00 |
|
Ege Balcı
|
20ca3b8720
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:17:37 +00:00 |
|
Ege Balcı
|
d8d5049d97
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:16:32 +00:00 |
|
Ege Balcı
|
4fe15ee788
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:16:21 +00:00 |
|
Ege Balcı
|
1a97b11f09
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:16:12 +00:00 |
|
Ege Balcı
|
86c8f11e17
|
Update modules/exploits/linux/http/vmware_vrli_rce.rb
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-08-18 20:16:03 +00:00 |
|
Jack Heysel
|
900e418796
|
Land #18226, H2 Web Interface RCE
This PR adds a module to exploit an RCE feature in
the H2 databases Web Interface.
|
2023-08-15 16:23:09 -04:00 |
|
h00die
|
f125ad8870
|
review comments
|
2023-08-08 17:44:35 -04:00 |
|
h00die
|
7b024f21bd
|
apache nifi h2 rce
|
2023-08-08 17:44:35 -04:00 |
|
h00die
|
5cdac38ac0
|
apache nifi h2 rce
|
2023-08-08 17:44:35 -04:00 |
|
h00die
|
e8ce0454cd
|
review comments
|
2023-08-08 17:16:57 -04:00 |
|
h00die
|
dca125963c
|
metabase review comments
|
2023-08-08 17:16:57 -04:00 |
|
h00die
|
f30c996340
|
remove comment
|
2023-08-08 17:16:56 -04:00 |
|
h00die
|
9516592eb6
|
metabase setup token rce
|
2023-08-08 17:16:56 -04:00 |
|
h00die
|
7ceeb9f8de
|
review comments
|
2023-08-08 17:15:22 -04:00 |
|
h00die
|
67ea97d686
|
set right port
|
2023-08-08 17:15:22 -04:00 |
|
h00die
|
06a4433e2a
|
review comments
|
2023-08-08 17:15:22 -04:00 |
|
h00die
|
97daf47269
|
h2 web interface shell
|
2023-08-08 17:15:22 -04:00 |
|
Ege Balcı
|
340e4c0117
|
Make rubocop happy
|
2023-08-08 20:54:40 +02:00 |
|
Ege Balcı
|
d1f9f540c6
|
Add VMware vRealize Log Insight RCE exploit
|
2023-08-08 20:32:38 +02:00 |
|
h00die-gr3y
|
19ef0cc4f9
|
Added documentation and fixed a typo in the module description
|
2023-07-28 21:30:24 +00:00 |
|
h00die-gr3y
|
f282e1ab92
|
first drop of module
|
2023-07-28 20:14:44 +00:00 |
|
ErikWynter
|
f79b4331b8
|
code review fixes for wd_mycloud_unauthenticated_cmd_injection
|
2023-07-27 23:09:50 +03:00 |
|
ErikWynter
|
53b8653ac7
|
add wd_mycloud_unauthenticated_cmd_injection
|
2023-07-26 17:24:44 +03:00 |
|
Christophe De La Fuente
|
c7f8ce5acd
|
Land #18199, VMWare vRealize Network Insight pre-authenticated RCE CVE-2023-20887
|
2023-07-25 17:45:30 +02:00 |
|
Jack Heysel
|
ee26e7f926
|
Rubocop fixes
|
2023-07-20 16:40:28 -04:00 |
|
Jack Heysel
|
421b06119f
|
Update docs
|
2023-07-20 14:55:27 -04:00 |
|
Jack Heysel
|
c48346413c
|
Fixed payload and verion detection
|
2023-07-20 14:44:56 -04:00 |
|
h00die
|
530934f78a
|
review comments
|
2023-07-19 11:42:47 -04:00 |
|
space-r7
|
7af22bfd41
|
Land #18077, add Symmetricom unauth cmd injection
|
2023-06-13 17:07:16 -05:00 |
|
space-r7
|
5535401345
|
add exploit rank
|
2023-06-13 17:05:30 -05:00 |
|
Steve Campbell
|
37bc9cd5a4
|
Update symmetricom_syncserver_rce.rb
Updated info to add allowed SRVPORT and LPORT, and fixed issue with srvport variable not used.
|
2023-06-13 16:22:08 -04:00 |
|
space-r7
|
cbf7109c51
|
add rubocop fixes and some metadata
|
2023-06-13 13:44:23 -05:00 |
|