msutovsky-r7
9caa2be9a2
Land #20399 , adds module for Pandora ITSM authenticated RCE (CVE-2025-4653)
...
Pandora ITSM auth RCE [CVE-2025-4653]
2025-08-07 08:37:45 +02:00
Chocapikk
6ff04da954
Add LPE suggestions in documentation
2025-08-04 18:33:28 +02:00
Chocapikk
7d744c2a45
Update documentation
2025-08-04 17:51:42 +02:00
Valentin Lobstein
c8f756dd37
Update documentation/modules/exploit/linux/http/ictbroadcast_unauth_cookie.md
...
Co-authored-by: msutovsky-r7 <martin_sutovsky@rapid7.com >
2025-08-04 17:02:12 +02:00
Chocapikk
50ef5edd90
Add Unauthenticated ICTBroadcast Remote Code Execution (CVE-2025-2611)
2025-08-02 19:46:14 +02:00
h00die-gr3y
4b52708357
update module + documentation based on review comments
2025-07-30 11:39:20 +00:00
jheysel-r7
05f2012ccc
Merge pull request #20338 from Chocapikk/xorcom
...
Add auxiliary and exploit modules for Xorcom CompletePBX 5.2.35 CVEs (2025-2292, 30004, 30005)
2025-07-22 08:19:36 -07:00
h00die-gr3y
58704e9eab
init module + documentation
2025-07-20 19:06:01 +00:00
adfoster-r7
8fe815da6f
Merge pull request #20394 from cgranleese-r7/update-docs-to-reflect-new-default-prompt
...
Updates docs to reflect new default prompt
2025-07-17 12:53:02 +01:00
cgranleese-r7
adff497bd2
Updates msf5 as well
2025-07-17 11:51:29 +01:00
Diego Ledda
18d61d3763
Merge pull request #20356 from msutovsky-r7/exploit/pandorafms_netflow_rce
...
Add module for authenticated PandoraFMS command injection (CVE-2025-5306)
2025-07-17 11:58:54 +02:00
Diego Ledda
ca9535e39a
Update pandora_fms_auth_netflow_rce.md
2025-07-17 11:29:07 +02:00
cgranleese-r7
469f102596
Updates docs to reflect new default prompt
2025-07-17 09:53:40 +01:00
Chocapikk
b06903810c
feat(xorcom): add shared CompletePBX mixin, refactor modules, update docs
2025-07-16 21:25:17 +02:00
Martin Sutovsky
f773e3aef9
Updates docs
2025-07-16 12:25:28 +02:00
msutovsky-r7
ffdfa07954
Land #20354 , adds module for ISPConfig code injection (CVE-2023-46818)
...
Add module for ISPConfig Code Injection (CVE-2023-46818)
2025-07-09 07:47:56 +02:00
Martin Sutovsky
ffa2152a6a
Updates docs
2025-07-07 11:56:53 +02:00
Martin Sutovsky
5c8d918e3d
Fixes documentation
2025-06-28 17:07:44 +02:00
happybear-21
840ae0f317
resolved: issues
2025-06-27 19:42:35 +05:30
Martin Sutovsky
37e8780a6b
Code refactor, docs
2025-06-27 10:26:31 +02:00
Martin Sutovsky
7b845fa3df
Fixed documentation issues
2025-06-26 12:08:51 +02:00
Martin Sutovsky
240bc828f1
Removing header
2025-06-26 12:08:51 +02:00
happybear-21
d787444137
Add exploit module for ISPConfig language_edit.php PHP Code Injection (CVE-2023-46818)
...
- Adds modules/exploits/linux/http/ispconfig_lang_edit_php_code_injection.rb
- Adds documentation for the module in documentation/modules/exploit/linux/http/ispconfig_lang_edit_php_code_injection.md
- Module targets ISPConfig < 3.2.11p1 with admin_allow_langedit enabled
- References and implementation based on PoC and advisories at https://github.com/SyFi/CVE-2023-46818
2025-06-25 22:27:52 +05:30
msutovsky-r7
fdc78b40bb
Add more clear installation steps
...
Co-authored-by: Diego Ledda <diego_ledda@rapid7.com >
2025-06-25 15:17:58 +02:00
Martin Sutovsky
ca142599e8
Module init
2025-06-23 10:27:27 +02:00
Chocapikk
2a008c83d1
Add auxiliary and exploit modules for Xorcom CompletePBX 5.2.35 CVEs (2025-2292, 30004, 30005, 30006)
2025-06-22 09:07:20 +02:00
msutovsky-r7
5fbf46ba7f
Land #19472 , adds exploits/linux/local/udev_persistence
...
Add modules/exploits/linux/local/udev_persistence.rb
2025-06-04 13:21:04 +02:00
Brendan
76471731f9
Merge pull request #20112 from cdelafuente-r7/mod/ivanti/rce/cve_2025_22457
...
Ivanti Connect Secure Unauthenticated RCE via Stack-based Buffer Overflow CVE-2025-22457
2025-05-15 11:44:49 -05:00
Christophe De La Fuente
365caab8fc
Update the error message in case of Broken pipe error and update the documentation
2025-05-15 12:10:53 +02:00
jheysel-r7
4b9032a487
Merge pull request #20060 from mekhalleh/rce_cve-2025-21293
...
Added exploit module for CVE-2025-32433 (Erlang/OTP)
2025-05-02 07:05:30 -07:00
Christophe De La Fuente
d83e6072ef
Add the module and documentation for Ivanti RCE CVE-2025-22457
2025-04-30 22:02:16 +02:00
Chocapikk
39a5d710aa
Refactor module: modularization, session-path leak, randomized key, improved check
...
- Centralized fetch_cookies_and_csrf and execute_via_session methods for clarity
- Added leak_session_path() to call send_transform("phpinfo") and parse session.save_path via XPath
- In check(): first try to leak the PHP session directory (report vulnerable if successful), then perform a simple RCE check by summing two 4-digit random numbers with print_r()
- Stub injection now happens once in fetch_cookies_and_csrf; execute_via_session only needs the payload
- Randomized the "as hack" key in send_transform
- Simplified exploit() to reuse execute_via_session with a Base64-encoded payload
- Big thanks to @jvoisin for the suggestions!
2025-04-30 00:24:25 +02:00
Chocapikk
f24801a4a4
Update doc
2025-04-29 20:06:40 +02:00
RAMELLA Sebastien
32a8e6797e
fixes review
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-27 20:31:13 +04:00
Chocapikk
89404c28e1
Fix markdown
2025-04-26 23:55:00 +02:00
Chocapikk
b8d2681335
Remove useless config suggestions
2025-04-26 23:53:59 +02:00
Chocapikk
c4e621f3cf
Add new exploit for CVE-2025-32432: Craft CMS Preauth RCE
2025-04-26 05:43:13 +02:00
RAMELLA Sebastien
740a8130d4
combine modules
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-25 10:35:16 +04:00
RAMELLA Sebastien
0a428b8d03
add scanner capability + code review
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-20 18:02:52 +04:00
RAMELLA Sebastien
59ed219775
Added exploit module for CVE-2025-21293 (Erlang/OTP)
...
Signed-off-by: RAMELLA Sebastien <sebastien.ramella@pirates.re >
2025-04-19 00:18:46 +04:00
Takah1ro
e1b5109c70
Add BentoML RCE module (CVE-2025-32375)
2025-04-17 20:46:43 +09:00
Takah1ro
edcc30699a
Make user be able to specify a particular endpoint
2025-04-16 21:47:31 +09:00
Takahiro Yokoyama
8dc4beba7f
Update documentation/modules/exploit/linux/http/bentoml_rce_cve_2025_27520.md
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2025-04-16 20:48:34 +09:00
Takah1ro
a33a8d91fe
Update the document
2025-04-16 12:52:15 +09:00
Takah1ro
e51cd24383
Add BentoML RCE module (CVE-2025-27520)
2025-04-15 22:46:42 +09:00
msutovsky-r7
fe9a0ad25b
Land #20008 , PandoraFMS Auth RCE module
...
Pandora FMS authenticated RCE [CVE-2024-12971]
2025-04-08 07:50:28 +02:00
h00die-gr3y
76fb34a5db
small update in description of the module and documentation
2025-04-06 10:49:03 +00:00
h00die-gr3y
8a72fd6861
init module and documentation
2025-04-06 10:33:56 +00:00
Takah1ro
139dd50333
Add Appsmith RCE module (CVE-2024-55964)
2025-04-05 14:56:04 +09:00
jheysel-r7
08e227faca
Merge pull request #19934 from sfewer-r7/bugfix-cisco-iosxe-rce
...
Improve exploit/linux/misc/cisco_ios_xe_rce (CVE-2023-20198 + CVE-2023-20273)
2025-03-27 16:51:16 -07:00