Graeme Robinson
f6f78d4710
Make changes suggested in code review
2020-11-26 13:46:02 +01:00
Graeme Robinson
7fa10a0684
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:02 +01:00
Graeme Robinson
5dc7e8f04e
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:02 +01:00
Graeme Robinson
78c042cbb7
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:01 +01:00
Graeme Robinson
7894f1eb9a
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:01 +01:00
Graeme Robinson
fcde932e1b
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:01 +01:00
Graeme Robinson
2a9898df25
Update modules/exploits/multi/http/apache_nifi_processor_rce.rb
...
Co-authored-by: cdelafuente-r7 <56716719+cdelafuente-r7@users.noreply.github.com >
2020-11-26 13:46:01 +01:00
Graeme Robinson
9a35a5fdee
Remove frozen_string_literal directive
...
Remove directive that was added by `rubocop -A`, as suggested in review.
Note that this results in an additional offense being reported by rubocop
2020-11-26 13:46:01 +01:00
Graeme Robinson
e33a2ca463
Use cleanup method to perform cleanup
2020-11-26 13:46:01 +01:00
Graeme Robinson
f6d39147af
Removed pointless comment.
2020-11-26 13:46:01 +01:00
Graeme Robinson
2de77b6e8a
Refactored code. Primarily line length increased.
2020-11-26 13:46:01 +01:00
Graeme Robinson
012b040fc1
Reformat code layout to satisfy msftidy
2020-11-26 13:46:01 +01:00
Graeme Robinson
41ff86178b
Add new module exploit module
...
Add new module /exploits/multi/http/apache_nifi_processor_rce.rb
2020-11-26 13:46:01 +01:00
Grant Willcox
63a98adff0
Land #14427 , phpstudy_backdoor_rce.rb TARGETURI handling and default value modifications
2020-11-25 10:32:53 -06:00
Grant Willcox
ca28f59ac4
Update the description of the TARGETURI option to reflect the recent changes
2020-11-25 10:32:17 -06:00
Spencer McIntyre
95665e916c
Land #14416 , wordpress plugin 'simple file list' rce
2020-11-25 09:58:26 -05:00
Spencer McIntyre
94c157bc95
Tweak the documentation and module output just a little for clarity
2020-11-25 09:58:07 -05:00
cgranleese-r7
31426576e0
Land #14264 , Add exploit/multi/http/kong_gateway_admin_api_rce
2020-11-25 11:09:02 +00:00
Natto
c8fc5b52cf
TARGETURI Default value modification
...
TARGETURI Default value modification
2020-11-24 14:05:49 +08:00
Graeme Robinson
8e299de712
Update modules/exploits/multi/http/kong_gateway_admin_api_rce.rb
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2020-11-22 14:49:51 +00:00
h00die
a988e85d90
remove not needed code
2020-11-22 09:07:11 -05:00
h00die
92c92f1573
simple file list rce
2020-11-21 08:51:07 -05:00
William Vu
72a6993408
Add patch bypass (CVE-2020-14750) to references
...
We were already using it... but now there's a CVE.
2020-11-18 10:57:05 -06:00
William Vu
78999bb92c
Add an exploit from Exploit-DB
...
Written by either (Nguyen) Jang or Mohammed Althibyani. Not used by the
module.
https://www.exploit-db.com/exploits/48971
2020-11-18 10:56:03 -06:00
William Vu
83beae731f
Add WebLogic Administration Console Handle RCE
...
CVE-2020-14882
CVE-2020-14883
2020-11-18 10:56:02 -06:00
Christophe De La Fuente
d6b412c58e
Land #14340 , Add HorizontCMS 1.0.0-beta exploit module and documentation
2020-11-13 13:03:04 +01:00
kalba-security
ce7031e263
Add suggestions from code review
2020-11-11 07:41:22 -05:00
h00die
768fb7d3a7
remove cwe-74 from cmsms
2020-11-10 11:43:42 -05:00
Shelby Pace
65e1ef4cb8
Land #14253 , add wp-file-manager rce for wordpress
2020-11-10 08:48:33 -06:00
Shelby Pace
4382f6ff55
add filedropper usage
2020-11-10 08:47:53 -06:00
kalba-security
e7a20ec47c
Add CVE ID to module and docs
2020-11-05 07:05:32 -05:00
Grant Willcox
a0087842fb
Fix an earlier merge mistake, was meant to replace URI.escape with Rex::Text.uri_encode() but instead replaced it with CGI.escape. Fix it to be Rex::Text.uri_encode()
2020-11-04 14:39:16 -06:00
Grant Willcox
d50ac2972d
Land #14222 , Update php_fpm_rce.rb to replace depreciated URI.encode calls with Rex::Text::uri_encode
2020-11-04 14:04:28 -06:00
Shelby Pace
79e83cdceb
add rubocop change
2020-11-04 10:09:00 -06:00
Shelby Pace
e49d99a80d
add AutoCheck usage, minor changes
2020-11-04 10:04:14 -06:00
kalba-security
cf954888da
Add horizontcms_upload_exec module and documentation
2020-11-02 13:01:13 -05:00
Graeme Robinson
bb9464801e
Make changes suggested in review
...
* Add better explanation of public-api-port option in documentation
* Add example in scenarios where admin API is on different host to
public API (therefore public-api-port option must be used)
* Add targeturi option
* Add version number that has been tested in 2 places in documentation
2020-10-27 21:13:45 +00:00
h00die
79384e85f3
remove old .keep files in non-empty directories
2020-10-24 09:41:55 -04:00
Grant Willcox
849dbeca5c
Fix up bad merge commit
2020-10-15 11:53:39 -05:00
ide0x90
d6a91f8965
Remove some unnecessary comments
2020-10-16 00:34:12 +08:00
ide0x90
8d02a1a4c6
Use Rex::MIME for building MIME message
2020-10-16 00:26:10 +08:00
Tim W
87104a7236
Update docs and make them msftidy_docs.rb compliant
2020-10-15 10:59:46 -05:00
Grant Willcox
f2899186e4
Add in first round of initial updates to fix review comments
2020-10-15 10:59:40 -05:00
Tim W
dcc322436b
Update documentation files and module description to more accurately describe what the cause of the LPE bug for CVE-2019-1458 is. also apply RuboCop edits.
2020-10-15 10:58:58 -05:00
Tim W
c38064b022
Apply rubocop edits and update documentation
2020-10-15 10:58:38 -05:00
Tim W
a3772d43d4
set InitialAutoRunScript to post/windows/manage/priv_migrate
2020-10-15 10:58:08 -05:00
Tim W
12c5f4f916
CVE-2019-1458 chrome sandbox escape initial commit
2020-10-15 10:57:46 -05:00
ide0x90
8d43fa4848
Module can now use mkfile+put method to exploit vulnerability.
2020-10-15 17:46:40 +08:00
Graeme Robinson
a8341d72ae
skip cleanup when using check method
2020-10-14 17:17:09 +01:00
Graeme Robinson
97f9c67ff1
Use class's cleanup method
2020-10-14 16:25:42 +01:00