William Vu
e0a67f4fd1
Land #13300 , IBM DRM RCE
2020-05-05 12:07:15 -05:00
Pedro Ribeiro
a17d78a327
Address review comments
...
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update documentation/modules/exploit/linux/http/ibm_drm_rce.md
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update ibm_drm_rce.md
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
make final changes!
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
Update modules/exploits/linux/http/ibm_drm_rce.rb
Co-authored-by: wvu-r7 <wvu-r7@users.noreply.github.com >
final final final
2020-05-05 10:53:08 -05:00
gwillcox-r7
d2b196f172
Land #13353 , Trixbox CE endpoint_devicemap.php Authenticated RCE
2020-05-04 16:11:05 -05:00
Anastasios Stasinopoulos
18ebf5efa6
Trixbox CE <= v2.8.0.4 Authenticated RCE
...
This module exploits a post-authentication OS command injection vulnerability found in Trixbox CE <= v2.8.0.4 which may allow arbitrary command execution on the underlying operating system.
2020-05-04 15:58:38 -05:00
William Vu
0bcc473ded
Rename option to HOSTINFO_NAME and update doc
2020-05-01 12:59:01 -05:00
William Vu
b2355568f8
Update module doc
2020-05-01 12:19:12 -05:00
William Vu
84061881b8
Clarify module description
2020-05-01 12:19:12 -05:00
William Vu
64f4cb7e41
Add module doc
2020-05-01 12:19:12 -05:00
bwatters-r7
686c2f09a1
Land #13290 , Cve-2014-2630 HP xglance-bin linux priv esc
...
Merge branch 'land-13290' into upstream-master
2020-05-01 10:18:21 -05:00
William Vu
4d635cdcfc
Update module doc
2020-05-01 04:28:17 -05:00
Spencer McIntyre
3e51730ae3
Land #11359 , Add the shiro_rememberme_v124_deserialize module
2020-04-28 15:35:06 -04:00
Spencer McIntyre
2c61fd0aff
Update Apache Shiro RCE module docs
2020-04-28 14:24:17 -04:00
William Vu
1318faa992
Clarify the quote is from the vendor's advisory
2020-04-27 16:53:34 -05:00
William Vu
cefeb9ffde
Randomize dir in desktopcentral_deserialization
...
Also apply RuboCop.
2020-04-27 16:13:22 -05:00
L
70ad79dbcc
change ip
2020-04-27 10:50:09 -05:00
L
b283442845
Add shiro_rememberme_v124_deserialize documentation
2020-04-27 10:50:09 -05:00
Shelby Pace
640eb77403
Land #13260 , add docker wincred module
2020-04-24 10:02:38 -05:00
Shelby Pace
24eeba09e8
typo
2020-04-24 10:01:31 -05:00
bwatters-r7
1c757f90db
bcoles suggestions
2020-04-22 18:08:58 -05:00
William Vu
823c29a127
Update post-RuboCop style in my recent modules
...
Mostly 80 columns (yeah, I know) and additional whitespace to complement
the lack of alignment.
2020-04-22 10:52:00 -05:00
Pedro Ribeiro
e75a6420a7
Create ibm_drm_rce.md
2020-04-21 15:50:38 +07:00
William Vu
c5df5355ac
Update my module documentation to the new standard
...
Also update CheckModule to match current style and best practices.
2020-04-20 20:06:52 -05:00
h00die
40095a8d05
glance variable
2020-04-19 22:54:38 -04:00
h00die
2772beac45
doc fix
2020-04-19 15:28:56 -04:00
h00die
e1f1ad45bc
working exploit
2020-04-19 15:19:19 -04:00
h00die
58074dc6bb
waiting on metasm question
2020-04-18 20:26:45 -04:00
gwillcox-r7
d759fbaed3
Land #13259 , Miscellaneous fixes for @wvu's modules and documentation
2020-04-16 22:10:10 -05:00
William Vu
966194d2b7
Remove tested admin password from default PASSWORD
2020-04-16 21:45:44 -05:00
William Vu
de116fc6be
Refactor setup section in Nexus module doc
2020-04-16 21:24:31 -05:00
bwatters-r7
b5df7e8147
Land #13102 , Add UnRAID 6.8.0 Authentication bypass to RCE
...
Merge branch 'land-13102' into upstream-master
2020-04-16 17:18:55 -05:00
bwatters-r7
15f4f7ea95
Land #13049 , Add fileformat exploit for libnotify plugin
...
Merge branch 'land-13049' into upstream-master
2020-04-16 16:03:14 -05:00
bwatters-r7
a18a5fab68
Rubocop autocorrect and update docs to use ascending numbers
2020-04-16 16:00:56 -05:00
Spencer McIntyre
fe8a191eed
Fix the fixed version for CVE-2020-7350
2020-04-16 15:45:48 -04:00
Spencer McIntyre
286a83afee
Add module documentation and fix the payload CachedSize value
2020-04-16 15:00:18 -04:00
Spencer McIntyre
62a000fe32
Land #13193 , add updates to the trusted service path LPE
2020-04-16 11:41:02 -04:00
William Vu
cd9e5260f7
Note post-auth requirements in Nexus exploit
2020-04-15 20:25:05 -05:00
William Vu
4401e3654f
Merge remote-tracking branch 'upstream/master' into bug/misc
...
So we can grab the Nexus files from master.
2020-04-15 20:24:44 -05:00
William Vu
820306919c
Reword setup section, once more with feeling
2020-04-15 18:57:47 -05:00
William Vu
7c678e61c3
Add note about getting/changing the admin password
2020-04-15 18:32:50 -05:00
William Vu
b7501c1f0c
Add my standard print for CmdStager
...
And comment some methods used by it.
2020-04-15 18:06:48 -05:00
bwatters-r7
9bede45746
Word
2020-04-15 17:01:32 -05:00
bwatters-r7
23cd4708c6
Forgot a step
2020-04-15 16:57:56 -05:00
bwatters-r7
2166ab04ac
First swipe at CVE-2019-15752
2020-04-15 16:52:45 -05:00
William Vu
17affae9c3
Add module doc
2020-04-15 15:49:45 -05:00
William Vu
66d5f51e51
Remove Nexus content from this branch
...
So the remaining changes can be PR'd separately.
2020-04-15 15:48:09 -05:00
William Vu
1368356d1b
Add note about installing Docker
2020-04-15 15:47:51 -05:00
William Vu
994097b410
Update all my module docs to use "options"
2020-04-15 15:47:51 -05:00
William Vu
28f279654c
Switch back to options (show options) in doc
2020-04-15 15:47:51 -05:00
William Vu
65d338d00e
Note tested version in module
2020-04-15 15:47:51 -05:00
William Vu
fbfd47684c
Update ManageEngine module doc to new standard
...
H3 for option names.
2020-04-15 15:47:51 -05:00