
Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads a web shell for remote command execution.
Proof of concept exploit for CVE-2019-10068, leveraging a Deserialization RCE in Kentico CMS to upload a web shell.
Legal Disclaimer: This proof-of-concept is provided for educational and authorised security research purposes only. The author is not responsible for any misuse or damage caused by this code, use it only on systems you own or have explicit permission to test and ensure compliance with all applicable laws.
https://target.com) on Line 9.python3 cve-2019-10068-poc.py.curl https://target.com/x.aspx?c=whoami.Happy pwnage!