
TeamCity CVE-2023-42793 RCE (Exécution de code à distance)
TeamCity CVE-2023-42793 RCE (Exécution de code à distance)
rce.pyInspiré par - https://www.prio-n.com/blog/cve-2023-42793-attacking-defending-JetBrains-TeamCity
python3 rce.py --url teamcity.runner.htb --command whoami
exploit.pyCe script est une copie de https://www.exploit-db.com/exploits/51884 fait par ByteHunter.
Le script retourne des identifiants de connexion, ce n'est pas une RCE !
python3 exploit.py -u teamcity.runner.htb
UTILISER UNIQUEMENT À DES FINS ÉDUCATIVES !
NOTE: Cet exploit est créé en tant que PoC ; utilisez-le uniquement à des fins éducatives ou pour des CTFs - https://flojboj.org/article/Runner