Brendan Coles
|
bdc2041c83
|
Add Klog Server authenticate.php user Unauthenticated Command Injection
|
2021-02-12 17:07:52 +00:00 |
|
Christophe De La Fuente
|
85b7e85d0b
|
Land #14671, Micro Focus Multiple Products Authenticated RCE (CVE-2020-11853)
|
2021-02-09 18:24:57 +01:00 |
|
Pedro Ribeiro
|
79cac47ba3
|
add suggestions by cdelafuente-r7
|
2021-02-09 14:24:49 +07:00 |
|
Spencer McIntyre
|
7281d00938
|
Implement feedback from PR review
|
2021-02-04 09:25:40 -05:00 |
|
Spencer McIntyre
|
c33c08bae9
|
Add a check method using the version information
|
2021-02-03 18:16:13 -05:00 |
|
Spencer McIntyre
|
c590d7b1bb
|
Add module docs and be more permissive with Length formatting
|
2021-02-03 18:16:13 -05:00 |
|
Pedro Ribeiro
|
33edfaa8f6
|
mention that it has been tested on 2019.11 too
|
2021-01-30 21:47:31 +07:00 |
|
Pedro Ribeiro
|
b8fe5fabf8
|
fix typo another typo
|
2021-01-28 22:50:05 +07:00 |
|
Pedro Ribeiro
|
446316ef6c
|
fix typo at the end of app list
|
2021-01-28 22:49:32 +07:00 |
|
Pedro Ribeiro
|
dcd9a6a214
|
add more clarification regarding affected products
|
2021-01-28 20:41:08 +07:00 |
|
Pedro Ribeiro
|
7ea5c3ffce
|
add clarification about c3p0
|
2021-01-28 18:23:20 +07:00 |
|
Pedro Ribeiro
|
c73fa70543
|
do the rubocop thing and add docs
|
2021-01-28 18:21:51 +07:00 |
|
bwatters
|
9174958489
|
Land #14627, Add PRTG Network Monitor RCE (CVE-2018-9276)
Merge branch 'land-14627' into upstream-master
|
2021-01-27 15:48:27 -06:00 |
|
Spencer McIntyre
|
74898461b4
|
Land #14654, Add exploit for Micro Focus UCMDB unauthenticated RCE
|
2021-01-27 10:00:22 -05:00 |
|
Spencer McIntyre
|
fc6957fbf6
|
Fix a couple of issues in the markdown formatting
|
2021-01-27 10:00:02 -05:00 |
|
adfoster-r7
|
ba730d5c3c
|
Land #14618, Add exploit for CVE-2020-28949: Archive_Tar PEAR plugin arbitrary file write
|
2021-01-25 12:12:12 +00:00 |
|
Pedro Ribeiro
|
7220dc3ff6
|
add new note on broken payloads
|
2021-01-24 22:39:01 +07:00 |
|
Pedro Ribeiro
|
12157163f7
|
Merge branch 'obm_deser' into ucmdb
|
2021-01-24 22:25:57 +07:00 |
|
Pedro Ribeiro
|
bf4ac7b1a8
|
add UCMDB sploit
|
2021-01-24 22:25:45 +07:00 |
|
Grant Willcox
|
0ec99c03f9
|
Clean up documentation formatting a little bit
|
2021-01-22 14:27:57 -06:00 |
|
William Vu
|
00cbc33ebb
|
Add module doc
|
2021-01-22 01:06:14 -06:00 |
|
William Vu
|
7ce10f68ae
|
RuboCop for great justice
And update docs.
|
2021-01-21 10:44:18 -06:00 |
|
William Vu
|
a336ee483a
|
Update exploit/unix/smtp/opensmtpd_mail_from_rce
Failure was caused by POSIX read requiring an argument.
|
2021-01-21 03:56:19 -06:00 |
|
JulienBedel
|
8f6dd43025
|
Add documentation
|
2021-01-18 12:02:46 +01:00 |
|
Grant Willcox
|
95d3bd98ac
|
Do msftidy_docs and rubocop changes
|
2021-01-15 18:10:23 -06:00 |
|
Grant Willcox
|
2f0abe4900
|
Add in documentation and fix up small issues with module
|
2021-01-15 18:06:07 -06:00 |
|
Christophe De La Fuente
|
c8819259ae
|
Land #14414, CVE-2020-1337 - patch bypass for CVE-2020-1048
|
2021-01-15 19:13:14 +01:00 |
|
bwatters
|
d8e68e6487
|
Specify you must be SYSTEM for dll removal in docs and removed unused variable in the module
|
2021-01-12 11:45:53 -06:00 |
|
Spencer McIntyre
|
33bd712e0a
|
Land #14585, Create module for CVE-2020-17136: Cloud Filter Arbitrary File Creation EoP
|
2021-01-11 17:16:40 -05:00 |
|
bwatters
|
50e115b414
|
Cleanup and edits per review from Christophe
Removed unused method from ps script
Cleaned up some code in the module
Added removal instructions to the documentation
|
2021-01-11 16:02:58 -06:00 |
|
Shelby Pace
|
7aef731267
|
Land #14572, add AIT CSV import rce
|
2021-01-11 15:37:05 -06:00 |
|
h00die
|
7d7263cf1f
|
spelling
|
2021-01-09 08:13:19 -05:00 |
|
Grant Willcox
|
3072391d00
|
Make second round of review edits to fix Spencer's comments
|
2021-01-08 12:50:52 -06:00 |
|
Grant Willcox
|
3e52debd8b
|
Update the exploit a bit more to remove excess options and also update the documentation accordingly.
|
2021-01-06 12:16:06 -06:00 |
|
Christophe De La Fuente
|
17c393f101
|
Land #14046, Adding juicypotato-like privilege escalation exploit for windows
|
2021-01-06 16:02:05 +01:00 |
|
Grant Willcox
|
863417fca7
|
Second round of updates and some rubocop changes to conform to standards.
|
2021-01-06 01:30:40 -06:00 |
|
Grant Willcox
|
81ee149ea2
|
Add check code support to module and update the documentation accordingly, plus rework the module description
|
2021-01-06 01:06:08 -06:00 |
|
bwatters
|
54f5e565fa
|
Land #14330, SpamTitan Gateway Remote Code Execution
Merge branch 'land-14330' into upstream-master
|
2021-01-04 12:14:12 -06:00 |
|
h00die
|
d8c55501a5
|
ait csv improter exploit
|
2021-01-01 12:14:52 -05:00 |
|
Grant Willcox
|
7de662c807
|
Land #14521, Struts2 Multi Eval OGNL RCE
|
2020-12-23 11:40:16 -06:00 |
|
Grant Willcox
|
70f8ff31f8
|
Update documentation to include missing extra options I forgot to document, edit the wording on the module to match the documentation, and do final touch ups.
|
2020-12-23 10:50:22 -06:00 |
|
Grant Willcox
|
799b451324
|
Add in updates to documentation to fix spelling mistakes and to also add in missing documentation for some options, plus to make some explanations a bit clearer.
|
2020-12-22 17:33:40 -06:00 |
|
bwatters
|
d2ca5d331d
|
Add documentation
|
2020-12-22 14:14:20 -06:00 |
|
Grant Willcox
|
4a449f97d3
|
Land #14522, Replace hard-coded Shiro default key with ENC_KEY
|
2020-12-22 09:26:49 -06:00 |
|
Grant Willcox
|
24e8aeffe5
|
Incorporate review feedback and update the associated documentation.
|
2020-12-21 17:29:21 -06:00 |
|
William Vu
|
39110d04f0
|
Add note about needing an Oracle account
|
2020-12-18 21:20:29 -06:00 |
|
William Vu
|
4d85602fae
|
Fix incorrect scenario header in module doc
I retested in VirtualBox and updated the output but not the header.
|
2020-12-18 21:15:05 -06:00 |
|
C4ssandre
|
57c57a398d
|
Adding new check to filter out Windows 7 and Windows XP. Indeed, lab experiments has shown that BITS does not attempt to connect to WinRM port, making those systems not vulnerable.
|
2020-12-19 02:51:48 +01:00 |
|
Christophe De La Fuente
|
dc6b67f4c6
|
Land #14509, Fixes for Solr RCE
|
2020-12-18 21:51:06 +01:00 |
|
Spencer McIntyre
|
9b8b4621df
|
Land #14368, Pulse Connect Secure gzip RCE: cve-2020-8260
|
2020-12-17 17:43:55 -05:00 |
|