Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-24637 — Unauthenticated RCE in Open Web Analytics version <1.7.4 | Kitploit
Tools/GitHubGitHub/0xm4hm0ud/cve-2022-24637
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHub0xm4hm0ud/cve-2022-24637

CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

View Repository
3623 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

This script is made to automate the CVE-2022-24637 vulnerability. I created this exploit for my Hackthebox machine vessel. https://app.hackthebox.com/machines/Vessel

The exploit and idea is based on https://devel0pment.de/?p=2494

exploit

Run the script with the following parameters:

python3 exploit.py http://<url>/ newPassword YourIp YourPort

It might be possible that you need to run it a few times to get a shell.

The script can be improved.

img

Download Tool