bwatters
|
01a78f972c
|
Land #17567, ManageEngine Endpoint Central RCE (CVE-2022-47966)
Merge branch 'land-17567' into upstream-master
|
2023-02-08 13:06:53 -06:00 |
|
Spencer McIntyre
|
c997952d83
|
Land #17607, Fortra RCE CVE-2023-0669
Fortra deserialization RCE CVE-2023-0669 (ETR)
|
2023-02-08 12:56:09 -05:00 |
|
Spencer McIntyre
|
2b008af097
|
Move the module to reflect it targets Windows too
|
2023-02-08 10:24:27 -05:00 |
|
Spencer McIntyre
|
75ceb7b670
|
Refactor option handling.
Use CamelCase names for advaned options and add validation.
|
2023-02-08 10:17:16 -05:00 |
|
Spencer McIntyre
|
fef7c85518
|
Add Windows target compatibility
|
2023-02-08 09:47:37 -05:00 |
|
cgranleese-r7
|
10144a9f13
|
Land #17615, Add missing module notes for stability reliability and side effects
|
2023-02-08 12:28:47 +00:00 |
|
adfoster-r7
|
433bafdccf
|
Add missing module notes for stability reliability and side effects
|
2023-02-08 11:45:17 +00:00 |
|
bwatters
|
8ee67085c8
|
Land #17556, ManageEngine ADSelfService Plus RCE (CVE-2022-47966)
Merge branch 'land-17556' into upstream-master
|
2023-02-07 16:57:22 -06:00 |
|
Matthew Dunn
|
52fa2e5be6
|
Add example for version 5.5.6 with CVE-2021-25297
|
2023-02-07 14:18:53 -06:00 |
|
Grant Willcox
|
489ab24876
|
Add in additional case documentation for the various targets and CVEs and fix a bug in the code
|
2023-02-07 14:18:45 -06:00 |
|
Grant Willcox
|
7c30889784
|
Refactor code to handle unsigned licenses in one central function
|
2023-02-07 14:18:39 -06:00 |
|
Grant Willcox
|
b14bcd40a2
|
Fix incorrect match logic grabbing the wrong entry from results for NSP
|
2023-02-07 14:18:38 -06:00 |
|
Grant Willcox
|
425da60b15
|
Add in missing case 5 check
|
2023-02-07 14:18:38 -06:00 |
|
Matthew Dunn
|
90e07ef5ed
|
Switch to match over scan and add troubleshooting steps
|
2023-02-07 14:18:37 -06:00 |
|
Matthew Dunn
|
8cddf56238
|
Verify auth_cookies before use
|
2023-02-07 14:18:37 -06:00 |
|
Matthew Dunn
|
a276659681
|
Use more encompassing single regex
|
2023-02-07 14:18:36 -06:00 |
|
Matthew Dunn
|
7554b5e4fd
|
Add failure condition for nsp's that fail to match the regex
|
2023-02-07 14:18:36 -06:00 |
|
Matthew Dunn
|
1cb06b11ac
|
Adjust exploit and docs to support versions 5.5.6-5.7.5
|
2023-02-07 14:18:09 -06:00 |
|
Matthew Dunn
|
87176f9d7f
|
Address Review Comments and add CVE-2021-25297 coverage
|
2023-02-07 14:18:06 -06:00 |
|
Matthew Dunn
|
c5914d8c99
|
Insert randomized strings to fix exploit with plugin_output_len
|
2023-02-07 14:18:05 -06:00 |
|
Matthew Dunn
|
990db5372f
|
Remove extra payload details, add config check
|
2023-02-07 14:18:05 -06:00 |
|
Matthew Dunn
|
b042e71b2a
|
Make Module work for both target url parameters
|
2023-02-07 14:18:04 -06:00 |
|
Matthew Dunn
|
b606d1ff6b
|
Add Documentation for Module
Fix CVE format
Add Documentation
|
2023-02-07 14:18:04 -06:00 |
|
Matthew Dunn
|
5846d95b25
|
Create nagios_xi_configwizards_authenticated_rce.rb
Add initial module
|
2023-02-07 14:18:03 -06:00 |
|
Ron Bowes
|
676bb2af02
|
Fix a couple requests from the PR
|
2023-02-07 09:05:44 -08:00 |
|
Ron Bowes
|
588bddc950
|
Fix a couple requests from the PR
|
2023-02-07 09:05:16 -08:00 |
|
bwatters
|
53c67653f5
|
Land #17527, ManageEngine ServiceDesk Plus RCE (CVE-2022-47966)
Merge branch 'land-17527' into upstream-master
|
2023-02-06 17:37:31 -06:00 |
|
Ron Bowes
|
f7fb611bcc
|
Add documentation
|
2023-02-06 14:35:42 -08:00 |
|
Ron Bowes
|
89485703dc
|
Make rubocop happy
|
2023-02-06 14:23:55 -08:00 |
|
Ron Bowes
|
9b90343480
|
Check in the module
|
2023-02-06 14:21:42 -08:00 |
|
adfoster-r7
|
4a2dc0d6b0
|
Land #17598, modules/exploits/unix/local Add Notes and resolve RuboCop violations
|
2023-02-06 13:59:19 +00:00 |
|
h00die
|
a5a7d5dd10
|
correct cleanup and stabilization
|
2023-02-05 08:15:38 -05:00 |
|
bcoles
|
adf5091c7a
|
modules/exploits/unix/local: Add Notes and resolve RuboCop violations
|
2023-02-05 15:45:30 +11:00 |
|
h00die
|
561b42f105
|
use exploit retry function
|
2023-02-04 18:17:42 -05:00 |
|
h00die
|
aff14e8e46
|
tocat to tomcat
|
2023-02-04 18:17:42 -05:00 |
|
h00die
|
e30cae2e40
|
uncomment needed code
|
2023-02-04 18:17:42 -05:00 |
|
h00die
|
34b1e66f90
|
tomcat 8 priv esc on ubuntu prebuilt so file
|
2023-02-04 18:17:41 -05:00 |
|
h00die
|
2b09af78e1
|
tomcat 8 priv esc on ubuntu
|
2023-02-04 18:17:41 -05:00 |
|
cgranleese-r7
|
80dbbca020
|
Land #17371, Lenovo Diagnostics Driver Privilege Escalation (CVE-2022-3699)
|
2023-02-03 13:43:04 +00:00 |
|
Jack Heysel
|
6ab7e177f4
|
Land #17392, add F5 Big-IP priv esc module
Add a privilege escalation module for F5 that uses
the unsecured MCP socket to create a new root account
|
2023-02-02 15:10:33 -05:00 |
|
Jack Heysel
|
f4ad778bd0
|
Added missing session types
|
2023-02-02 13:29:43 -05:00 |
|
Jack Heysel
|
af2ef53462
|
Land #17415, macOS dirty cow priv esc
|
2023-02-02 12:15:19 -05:00 |
|
adfoster-r7
|
952a4fe37a
|
Land #17581, modules: Check datastore ForceExploit before checking if session is root
|
2023-02-02 10:19:07 +00:00 |
|
bcoles
|
6f4a17230d
|
exploits/osx/local/vmware_fusion_lpe: Add notes
|
2023-02-02 18:46:08 +11:00 |
|
bcoles
|
a83d070396
|
exploits/freebsd/local/ip6_setpktopt_uaf_priv_esc: Add Reliability notes
|
2023-02-02 18:45:43 +11:00 |
|
bcoles
|
ef87a63bde
|
modules: Check datastore ForceExploit before checking if session is root
|
2023-02-02 18:17:02 +11:00 |
|
Grant Willcox
|
48a27ab555
|
Fix the remaining references to the old wiki site.
|
2023-02-01 21:25:06 -06:00 |
|
adfoster-r7
|
6870efc34a
|
Land #17426, Update all references to old Wiki to point to new docs site
|
2023-02-01 23:49:20 +00:00 |
|
Jack Heysel
|
076ffbcc65
|
Merge branch 'mac_dirty_cow' of github.com:timwr/metasploit-framework into mac_dirty_cow
|
2023-02-01 16:57:36 -05:00 |
|
Jack Heysel
|
3c7cbf62e6
|
Updated default payload
|
2023-02-01 16:56:28 -05:00 |
|