Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2018-5767-AC9 — تنفيذ إثبات المفهوم لـ CVE-2018-5767 | Kitploit
أدوات/GitHubGitHub/scorpion-security-labs/cve-2018-5767-ac9
أمان الأنظمة المدمجةأمان إنترنت الأشياءالاستغلالاستغلال تطبيقات الويبأمن الأجهزةأداة الوصول عن بعداستغلال الملفات الثنائية
GitHubscorpion-security-labs/cve-2018-5767-ac9

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2018-5767-AC9

تنفيذ إثبات المفهوم لـ CVE-2018-5767

عرض المستودع
3منذ 2 سنواتلم تتم المراجعة بعد

البحث والمؤلف

  • David Baker
  • مقالة: أحيانًا تحتاج الاستغلالات إلى تصحيحات أيضًا! العمل من خلال تغيير العنوان (رابط خارجي)

CVE-2018-5767-AC9

root@kitploit:~
The following is an actualization of CVE-2018-5767, a vulnerability which
exploits an unguarded call to sscanf that occurs when parsing the 'Cookie'
header for a password. The vulnerability was initially discovered in, and
reported for, the AC15 model router, but has been rediscovered in several
different routers in this product line. This implementation sees it exploit the
model AC9, which is not presently covered by any CVE. A memory address for the
base of libc known to work on this router is 0x2ad6d000.

See the following for more information:
https://www.cve.org/CVERecord?id=CVE-2018-5767
https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767/
https://www.klogixsecurity.com/scorpion-labs-blog/sometimes-exploits-need-patches-too-working-through-a-change-of-address

usage: CVE-2018-5767-AC9.py [-h] [-t TARGET] [-p PORT] [-l LIBC] [-c COMMAND]
                            [-v] [-a]

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        target URL or IP address to throw against
  -p PORT, --port PORT  target port to throw against (default = 80)
  -l LIBC, --libc LIBC  estimated base address of libc (default = 0x2ad6d000)
  -c COMMAND, --command COMMAND
                        command(s) to be run on target (default = exit)
  -v, --verbose         increase output verbosity (currently not implemented)
  -a, --about           print information about this vulnerability then exit
تنزيل الأداة