Spencer McIntyre
|
78f97d2fa7
|
Land #15281, Add Cisco HyperFlex exploit
|
2021-06-03 17:24:27 -04:00 |
|
Shelby Pace
|
8b737c2c60
|
Land #15231, add SuiteCRM log file rce
|
2021-06-03 09:11:00 -05:00 |
|
William Vu
|
6efd312430
|
Add Cisco HyperFlex HX Data Platform exploit
CVE-2021-1497
CVE-2021-1498
|
2021-06-03 00:43:56 -05:00 |
|
William Vu
|
37a7ee2e28
|
Clean up f5_icontrol_rest_ssrf_rce
Escalate a warning and prefer a variable.
|
2021-06-02 20:32:47 -05:00 |
|
mcorybillington
|
d2b539e3c9
|
authentication fix from add cookie jar merge
|
2021-06-02 16:54:09 -05:00 |
|
Shelby Pace
|
3056e8f946
|
add cookie jar and AutoCheck
|
2021-06-02 13:09:33 -05:00 |
|
mcorybillington
|
dea7f50d36
|
Cover log file restoriation in all failure cases
|
2021-05-29 09:25:10 -05:00 |
|
M. Cory Billington
|
1451e9b56b
|
Update modules/exploits/linux/http/suitecrm_log_file_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-05-27 11:59:32 -05:00 |
|
M. Cory Billington
|
fa1ad1b32e
|
Update modules/exploits/linux/http/suitecrm_log_file_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-05-27 11:59:28 -05:00 |
|
M. Cory Billington
|
b4f699fb15
|
Update modules/exploits/linux/http/suitecrm_log_file_rce.rb
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2021-05-27 11:59:23 -05:00 |
|
mcorybillington
|
2d9fdb97ad
|
Check that initial request is valid
|
2021-05-26 12:23:36 -05:00 |
|
mcorybillington
|
57ef94cfdf
|
Remove non boolean return from authentication
|
2021-05-25 22:55:28 -05:00 |
|
mcorybillington
|
91284db05d
|
Check returned responses on each stage and output status info
|
2021-05-25 22:49:27 -05:00 |
|
mcorybillington
|
ed1f5db48d
|
Check method and authentication fixes
|
2021-05-25 20:38:32 -05:00 |
|
M. Cory Billington
|
01a8a6ab30
|
Remove unrequired reference to msfcore
|
2021-05-23 12:12:35 -05:00 |
|
M. Cory Billington
|
2757e7163c
|
Remove trailing white space found during msftidy
|
2021-05-22 18:44:15 -05:00 |
|
M. Cory Billington
|
81c056df3b
|
Removed unused return value
|
2021-05-22 01:32:17 -05:00 |
|
M. Cory Billington
|
963cea939f
|
Changed request method to preferred method
|
2021-05-22 01:29:24 -05:00 |
|
M. Cory Billington
|
ab5256a106
|
Use more robust version checking and add missing return statements.
|
2021-05-22 01:26:28 -05:00 |
|
M. Cory Billington
|
64f9ea0848
|
Update modules/exploits/linux/http/suitecrm_log_file_rce.rb
Change Metasploit download link to https
Co-authored-by: bcoles <bcoles@gmail.com>
|
2021-05-22 00:59:23 -05:00 |
|
M. Cory Billington
|
f27c0a481c
|
Update modules/exploits/linux/http/suitecrm_log_file_rce.rb
Co-authored-by: bcoles <bcoles@gmail.com>
|
2021-05-22 00:56:44 -05:00 |
|
M. Cory Billington
|
e62efe0690
|
Added module and documentation for SuiteCRM Log File RCE
|
2021-05-22 00:11:19 -05:00 |
|
Grant Willcox
|
e7983c3b6f
|
Land #15192, Enforce Style/RedundantBegin for new modules
|
2021-05-17 09:51:57 -05:00 |
|
adfoster-r7
|
ac2c467121
|
Land #15011, Enhance analyze command API to understand modules' needs
|
2021-05-14 14:30:33 +01:00 |
|
Alan Foster
|
100da2f1b1
|
Enforce Style/RedundantBegin for new modules
|
2021-05-13 04:01:03 +01:00 |
|
William Vu
|
637e9cff48
|
Update vmware_vrops_mgr_ssrf_rce documentation
|
2021-05-06 18:30:20 -05:00 |
|
Mehmet INCE
|
bf0551979f
|
Fix the module according to the review
|
2021-05-03 12:29:00 +03:00 |
|
Mehmet INCE
|
06157601df
|
Remove SCREEN_EFFECTS from sideeffects
|
2021-05-03 11:14:43 +03:00 |
|
Mehmet INCE
|
9e04805c0e
|
Adding check method to gravcms exec
|
2021-05-03 11:14:43 +03:00 |
|
Mehmet INCE
|
e3d05395de
|
Add GravCMS exec
|
2021-05-03 11:14:42 +03:00 |
|
William Vu
|
d433c0fd12
|
Fix typo
|
2021-04-30 23:29:24 -05:00 |
|
Spencer McIntyre
|
994825dcc9
|
Land #15090, Add exploit for CVE-2021-22502
|
2021-04-29 14:09:28 -04:00 |
|
Shelby Pace
|
a4af80d3e1
|
Land #15005, add VMware vRealize SSRF RCE
|
2021-04-27 09:19:55 -05:00 |
|
Shelby Pace
|
363db0e271
|
Land #14977, add Apache Druid js rce
|
2021-04-26 12:01:19 -05:00 |
|
Pedro Ribeiro
|
07d82cde93
|
fix timeout errors in rubocop
|
2021-04-23 22:10:38 +07:00 |
|
Pedro Ribeiro
|
02ce5a1724
|
Update modules/exploits/linux/http/microfocus_obr_cmd_injection.rb
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com>
|
2021-04-23 22:01:05 +07:00 |
|
Pedro Ribeiro
|
58e00b582e
|
Update modules/exploits/linux/http/microfocus_obr_cmd_injection.rb
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com>
|
2021-04-23 22:00:55 +07:00 |
|
Pedro Ribeiro
|
651a34af53
|
add sploit for MF OBR cmd injection
|
2021-04-23 21:04:36 +07:00 |
|
William Vu
|
a62d1dfbcd
|
Add some details back in
|
2021-04-21 16:02:21 -05:00 |
|
William Vu
|
5111caf536
|
Address @gwillcox-r7 review
New words from @gwillcox-r7.
|
2021-04-21 13:10:21 -05:00 |
|
William Vu
|
22433d5b2c
|
Add clarifying comment
|
2021-04-21 10:42:10 -05:00 |
|
William Vu
|
08907a5e3a
|
Add VMware vRealize Operations Manager SSRF RCE
CVE-2021-21975 + CVE-2021-21983
|
2021-04-21 10:42:10 -05:00 |
|
Grant Willcox
|
7b7e521d6c
|
Fix up a wrong type field value and set it back to 1 from 2 in the send_exploit() function, since this was causing the exploit to fail
|
2021-04-20 17:45:51 -05:00 |
|
Grant Willcox
|
e0f13e44d1
|
Land #14699, Add Nagios XI snmptrap RCE and docs (CVE-2020-5792)
|
2021-04-20 14:30:45 -05:00 |
|
Grant Willcox
|
f241a050b8
|
Apply review comments and fixes to documentation and the module
|
2021-04-20 12:38:34 -05:00 |
|
Grant Willcox
|
d60cdbebb3
|
Add in Regex fix to ensure that really old versions of NagiosXI will still be detected as vulnerable despite unusual version naming convention
|
2021-04-19 14:17:05 -05:00 |
|
Grant Willcox
|
4ac9304ca2
|
Land #14968 - Add Nagios XI Mibs.php Authenticated RCE module and docs (CVE-2020-5791)
|
2021-04-16 14:37:15 -05:00 |
|
Grant Willcox
|
496e074ec8
|
Add in fixes to documentation and module from review
|
2021-04-16 13:14:17 -05:00 |
|
William Vu
|
9e6f425427
|
Move exploit/linux/http/citrix_dir_traversal_rce
To exploit/freebsd/http/citrix_dir_traversal_rce. It's actually FreeBSD.
|
2021-04-15 19:13:25 -05:00 |
|
Grant Willcox
|
832ca92f42
|
Land #14700, Add Nagios XI Plugins Filename Authenticate RCE module and docs (CVE-2020-35578)
|
2021-04-14 16:58:55 -05:00 |
|