Commit Graph

13654 Commits

Author SHA1 Message Date
Lars Sorenson 143fdde1f8 Flipped Safe and Appears in check 2018-04-15 12:10:10 -04:00
Brendan Coles a60f205ee0 Fix check return CheckCode and typos 2018-04-15 18:08:49 +10:00
Lars Sorenson 60ac89c336 Restructure some logic to make the flow more intuitive 2018-04-14 15:03:12 -04:00
Lars Sorenson 36c1bf5453 Remove a missed tab 2018-04-14 10:30:49 -04:00
Lars Sorenson 083f6936fd Update for @bcoles review
Refactor version checking to use Gem::Version
Change the title of the exploit to fit convention
Change print statements used in check to vprint
Change fail_with Failure for connection issues to be Unknown instead
	of NoAccess
Add CVE reference
Refactor how some nil checking is done for response for
	send_request_cgi
Text-wrap description to 80 chars
Remove unnecessary string interpolation for cookie in payload
	delivery
Change how the payload cradle is escaped and encoded; switch to HTTP
	POST for stealth
Remove nil check that is redundant and also typo'd to
2018-04-14 10:24:05 -04:00
Lars Sorenson 486ab7c776 Update for msftidy and contribution guidelines 2018-04-14 09:20:13 -04:00
Lars Sorenson 27ded57cda Add MSF module for EDB 6768 2018-04-14 08:51:51 -04:00
William Vu d8508b8d7d Add Drupal Drupalgeddon 2 2018-04-14 00:22:30 -05:00
Brendan Coles 9a3064ad7e Cleanup and refactor upload_and_compile 2018-04-12 16:43:43 +00:00
Green-m 0286204b5d Couchdb debug code 2018-04-12 03:54:02 -04:00
Green-m 054e525a61 Couchdb debug code 2018-04-12 03:51:37 -04:00
h00die c72ca7544b dont let this run on meterpreter 2018-04-11 21:05:15 -04:00
Brendan Coles fc7040099c Update Linux sock_sendpage local exploit module 2018-04-10 11:15:42 +00:00
Green-m 3c5cbd2664 Use cmdstager method, update function to clean file, delete lots of useless code and etc. 2018-04-10 06:14:47 -04:00
Green-m c0be313691 Update the get_version and check function 2018-04-09 00:07:58 -04:00
Green-m 6682acc4db Pass range as parameter to rand_text_alpha_lower 2018-04-08 23:38:44 -04:00
Green-m d9dc2ec2f7 Merge branch 'master' into couchdb_cmd_exec 2018-04-08 23:35:04 -04:00
Green-m dabd9c8811 Improve function get_version and check 2018-04-08 07:51:37 -04:00
gushmazuko bd672ae148 Description changed 2018-04-08 12:00:14 +02:00
gushmazuko 1e439b623b Description changed 2018-04-08 11:46:01 +02:00
Green-m fd83caf51d use Gem::Version between 2018-04-08 02:23:45 -04:00
Green-m 076a73c2ee use Gem::Version for version comparisons 2018-04-07 23:37:56 -04:00
h00die dd523c7d20 compile path not local file 2018-04-06 18:51:04 -04:00
Daniel Teixeira 37c578e16d Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 17:10:53 +01:00
Daniel Teixeira dee01189ca Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 15:41:21 +01:00
Daniel Teixeira 50c3f53e03 Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 14:39:45 +01:00
Daniel Teixeira 0c829a5c6b Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 14:35:33 +01:00
Daniel Teixeira cbdb3a35b2 Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 14:14:11 +01:00
Daniel Teixeira 6698f1b64b Update oscommerce_installer_unauth_code_exec.rb 2018-04-06 13:05:40 +01:00
Daniel Teixeira 806c72ebcb Update and rename oscommerce.rb to oscommerce_installer_unauth_code_exec.rb 2018-04-06 11:29:29 +01:00
Daniel Teixeira 3efd17a801 Rename osCommerce.rb to oscommerce.rb 2018-04-06 10:46:00 +01:00
Daniel Teixeira 0d254b4e5c Update osCommerce.rb 2018-04-06 10:40:28 +01:00
Daniel Teixeira b5681cb954 osCommerce Module 2018-04-05 20:28:14 +01:00
Brent Cook 81c78a51c2 Land #9794, Added support for regional dialects 2018-04-05 12:56:07 -05:00
Green-m 0d470f67ef Run bash on the script directly. 2018-04-04 05:49:35 -04:00
Green-m c53341f6c0 Fix msftidy problem. 2018-04-04 00:38:57 -04:00
Green-m 388927b933 Add advanced option Attempts to control exploit times 2018-04-04 00:08:32 -04:00
Green-m 2472bfdfdc Fix rand_text_alpha_lower problem. 2018-04-03 23:05:08 -04:00
Green-m bbf6d072ea Fix some errors and bugs. 2018-04-03 22:47:41 -04:00
Chris Higgins 1fa40bfe3b Land #8539, ProcessMaker Plugin Upload exploit 2018-04-03 20:52:17 -05:00
Brent Cook 8f7d9f3ac8 rename module 2018-04-03 13:44:55 -05:00
Brent Cook 19eef59f23 add disclosure date, fix target 2018-04-03 13:39:11 -05:00
Brent Cook cd7831a2a3 An unforgettable luncheon 2018-04-03 13:39:11 -05:00
Brendan Coles dfb3a421fe Remove require statement 2018-04-03 12:56:06 +00:00
Brent Cook 8c2138f13b Land #9742, QNX exploit improvements 2018-04-03 07:50:29 -05:00
Tim W 9f174e7323 msftidy 2018-04-03 16:10:41 +08:00
Tim W 7c3e5da450 add more credits/references 2018-04-03 14:59:00 +08:00
Tim W c5039251a2 add CVE-2016-4655
rebase
2018-04-03 14:58:57 +08:00
Tim W d465226d89 add loader 2018-04-03 14:44:54 +08:00
Tim W cd1f4e1373 webkit apple safari trident exploit 2018-04-03 14:44:54 +08:00