Grant Willcox
|
f2a86327d0
|
Minor fixes from review
|
2023-02-09 15:34:25 -06:00 |
|
Stephen Wildow
|
427c181e9a
|
Utilized msftidy_docs.rb to clean up missing sections, excessively long lines, spaces at EOL, and space end of file. Removed credit section. Expanded on installation procedure. Modified steps procedure to include Verify options and removed failure status. Removed Targets section. Scenarios have device, target, and architecture.
|
2023-02-08 19:18:14 -05:00 |
|
Stephen Wildow
|
35749a000a
|
Added docs. Performed code linting with rubocop.
|
2023-02-07 20:27:07 -05:00 |
|
Jack Heysel
|
6ab7e177f4
|
Land #17392, add F5 Big-IP priv esc module
Add a privilege escalation module for F5 that uses
the unsecured MCP socket to create a new root account
|
2023-02-02 15:10:33 -05:00 |
|
adfoster-r7
|
6870efc34a
|
Land #17426, Update all references to old Wiki to point to new docs site
|
2023-02-01 23:49:20 +00:00 |
|
Ron Bowes
|
cf172d22c8
|
Get rid of #String.hash in favour of UnixCrypt
|
2023-02-01 11:02:04 -08:00 |
|
Ron Bowes
|
1094221468
|
Merge branch 'rapid7:master' into f5-createuser-privesc
|
2023-02-01 10:20:43 -08:00 |
|
Ron Bowes
|
638a1c519d
|
Update documentation/modules/exploit/linux/local/f5_create_user.md
Better demo exploit
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com>
|
2023-02-01 10:14:25 -08:00 |
|
h00die
|
5a374533af
|
cve-2022-1043
|
2023-01-31 16:02:25 -05:00 |
|
h00die
|
8d58eb6279
|
cve-2022-1043
|
2023-01-31 16:02:25 -05:00 |
|
Jack Heysel
|
022760d24a
|
Land #17300, linux LPE cve-2022-22942 module
This PR adds a linux priv esc against VMWare virtual machines
with kernel 4.14-rc1 - 5.17-rc1 due to a VMWare driver bug.
|
2023-01-31 14:07:55 -05:00 |
|
adfoster-r7
|
bbf17c167c
|
Land #17511, add exploit for CVE-2022-44877 command injection in CentOS Control Web Panel
|
2023-01-31 14:05:19 +00:00 |
|
Grant Willcox
|
6043d0ffba
|
Update all links from Wiki site to new docs site.
|
2023-01-27 09:58:53 -06:00 |
|
Spencer McIntyre
|
f81195d0cc
|
Fix a typo
|
2023-01-25 13:45:18 -05:00 |
|
space-r7
|
153af9fb68
|
Land #17407, add Cacti unauth command injection
|
2023-01-23 13:06:46 -06:00 |
|
Spencer McIntyre
|
6fe0933c1e
|
Add exploit for CVE-2022-44877
|
2023-01-20 09:04:24 -05:00 |
|
h00die
|
be7ca91a8f
|
cve-2022-22942
|
2023-01-17 15:30:36 -05:00 |
|
Grant Willcox
|
7e23c34e6c
|
Apply fixes per code review
|
2023-01-17 12:44:22 -06:00 |
|
h00die-gr3y
|
da3ae22135
|
added documentation
|
2023-01-17 12:44:20 -06:00 |
|
Grant Willcox
|
f39973de86
|
Fix up missing option in documentation and also add some additional validation on server response.
|
2023-01-04 17:02:05 -06:00 |
|
h00die-gr3y
|
c7b59b4815
|
updates based on gwillcox-r7 review comments
|
2023-01-04 17:02:04 -06:00 |
|
h00die-gr3y
|
6801cbd21e
|
updated Limitation section
|
2023-01-04 17:02:03 -06:00 |
|
h00die-gr3y
|
fc6acdab6a
|
added documentation
|
2023-01-04 17:01:59 -06:00 |
|
Christophe De La Fuente
|
20d70799a7
|
Land #17298, Add opentsdb_yrange_cmd_injection module and docs
|
2022-12-23 13:38:58 +01:00 |
|
ErikWynter
|
8f96746551
|
fix typo and add credit for discovery
|
2022-12-23 11:11:31 +02:00 |
|
ErikWynter
|
4c2dfe0279
|
add cacti_unauthenticated_cmd_injection
|
2022-12-22 17:55:45 +02:00 |
|
Ron Bowes
|
2ec77e6d95
|
Merge branch 'master' into f5-createuser-privesc
|
2022-12-15 13:11:26 -08:00 |
|
Christophe De La Fuente
|
e7e2849f6d
|
Land #17183, Zimbra fixes
|
2022-12-06 15:38:37 +01:00 |
|
bwatters
|
54cd055276
|
Land #17286, CVE-2021-22015 vCenter priv esc
Merge branch 'land-17286' into upstream-master
|
2022-12-05 09:31:01 -06:00 |
|
ErikWynter
|
78dfaa12ef
|
add opentsdb_yrange_cmd_injection module and docs
|
2022-11-24 21:37:24 +02:00 |
|
adfoster-r7
|
0aa0884e26
|
Land #17296, add warning about external links
|
2022-11-24 10:30:44 +00:00 |
|
Spencer McIntyre
|
6350daf2d8
|
Land #17273, F5 exploit module CVE-2022-41800
F5 exploit module CVE-2022-41800 (authenticated RCE in RPM code)
|
2022-11-23 17:57:18 -05:00 |
|
Ron Bowes
|
28a68ede8c
|
Merge branch 'master' into zimbra-fixes
|
2022-11-23 12:50:56 -08:00 |
|
Jeffrey Martin
|
453cfc5939
|
spelling change per review
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com>
|
2022-11-23 13:26:19 -06:00 |
|
Jeffrey Martin
|
cb8e023734
|
add warning about external links
Links to external resources not controlled by the project maintainers
are subject to bitrot and malicious take over. Warnings seem appropriate.
|
2022-11-23 12:08:05 -06:00 |
|
h00die
|
6877304bac
|
exploit for cve-2021-22015 vcenter priv esc
|
2022-11-20 11:29:49 -05:00 |
|
Ron Bowes
|
fc579fe3f4
|
Add a privesc module for F5, using the MCP protocol
|
2022-11-16 12:12:16 -08:00 |
|
Ron Bowes
|
d0e109b842
|
Check in exploit module for CVE-2022-41800
|
2022-11-16 12:04:18 -08:00 |
|
Ron Bowes
|
99e661cfcf
|
Check in exploit script for CVE-2022-41622 (CSRF into SOAP)
|
2022-11-16 11:58:15 -08:00 |
|
h00die-gr3y
|
bf0ed5b513
|
fixed some typos in documentation
|
2022-11-05 15:36:42 +00:00 |
|
h00die-gr3y
|
642a83bd0d
|
Updated module and added documentation
|
2022-11-05 15:14:31 +00:00 |
|
space-r7
|
197b37751b
|
Land #17174, add FLIR AX8 command injection module
|
2022-11-01 12:41:01 -05:00 |
|
jheysel-r7
|
cf27c34917
|
Update documentation/modules/exploit/linux/http/webmin_file_manager_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2022-11-01 10:40:01 -05:00 |
|
jheysel-r7
|
6a1af915f6
|
Update documentation/modules/exploit/linux/http/webmin_file_manager_rce.md
Co-authored-by: Shelby Pace <40177151+space-r7@users.noreply.github.com>
|
2022-11-01 10:40:01 -05:00 |
|
Jack Heysel
|
d79515c3fe
|
Fix file cleanup
|
2022-11-01 10:40:00 -05:00 |
|
Jack Heysel
|
ad5b03ed96
|
Finished TODOs and added docs
|
2022-11-01 10:40:00 -05:00 |
|
Ron Bowes
|
ab2042f34e
|
Add patch notes to the Slapper module documentation
|
2022-10-25 10:04:52 -07:00 |
|
Ron Bowes
|
3ac3fa6c32
|
Move the Zimbra Slapper doc to the right folder (Windows -> Linux)
|
2022-10-25 09:51:27 -07:00 |
|
h00die-gr3y
|
3e78229fc0
|
updated module and documentation
|
2022-10-25 13:33:52 +00:00 |
|
Jack Heysel
|
3bf4bd7d7d
|
Land #17162, add RCE module for CVE-2022-35914
This PR adds an RCE module for the php code injection
present in GLPI versions 10.0.2 and below
|
2022-10-24 12:18:34 -04:00 |
|