Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-44909 — orangescrum 1.8.0 - Remote Command Execution RCE (unauthenticated) | Kitploit
Tools/GitHubGitHub/g1thub3r1st4/cve-2021-44909
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubg1thub3r1st4/cve-2021-44909

CVE-2021-44909

orangescrum 1.8.0 - Remote Command Execution RCE (unauthenticated)

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-44909

Exploit Title: orangescrum 1.8.0 - Remote Command Execution RCE (unauthenticated)

  • Date: 03/12/2021
  • Vendor Homepage: https://www.orangescrum.org/
  • Software Link: https://github.com/Orangescrum/orangescrum
  • Version: 1.8.0
  • Tested on: Windows 10 x64 using XAMPP 7.4.23, Apache/2.4.48 (Win64) OpenSSL/1.1.1l PHP/7.4.2

Exploit Steps:

  1. Open http://localhost/orangescrum/install/index.php
  2. Craft your malicious PHP file
  3. Compress and upload the previous PHP file under the name "AddonInstaller-V1.6.zip"
  4. Ignore received errors and open http://localhost/orangescrum/install/files/
  5. Locate and call your PHP file
  6. Receive your shell
Download Tool