Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Cobaltstrike-RCE-CVE-2022-39197 | Kitploit
Tools/GitHubGitHub/purple-wl/cobaltstrike-rce-cve-2022-39197
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubpurple-wl/cobaltstrike-rce-cve-2022-39197

Cobaltstrike-RCE-CVE-2022-39197

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
13 years agoNot yet reviewed

Cobaltstrike RCE Vulnerability CVE-2022-39197 Reproduction

Vulnerability Brief

This vulnerability exists in the Cobalt Strike Beacon software and may allow an attacker to set a malformed username in the Beacon configuration, triggering XSS, which can lead to remote code execution on the Cobalt Strike server.

Screenshot: image

Obtain NTLMv2-SSP Hash, provided Cobalt Strike is running on Windows

image

References:

https://www.freebuf.com/vuls/345522.html

https://mp.weixin.qq.com/s?__biz=MzI5Nzc3NDEyNA==&mid=2247483757&idx=1&sn=2397d14549520bac3bd7bec10d433db3&chksm=ecaebc2edbd9353803e2a3f0f5f906121db63e30e76c58654169656e9e40d5c8b5b0e8b80813&token=1380424937&lang=zh_CN#rd

https://forum.butian.net/share/708

https://github.com/Sentinel-One/CobaltStrikeParser

https://github.com/LiAoRJ/CS_fakesubmit

Download Tool