Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2022-36804-PoC-Exploit — कुछ हद तक विश्वसनीय PoC एक्सप्लॉइट CVE-2022-36804 (BitBucket क्रिटिकल कमांड इंजेक्शन) के लिए | Kitploit
उपकरण/GitHubGitHub/benjaminhays/cve-2022-36804-poc-exploit
टोहीभेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणपेनिट्रेशन टेस्टिंगकमांड एंड कंट्रोल
GitHubbenjaminhays/cve-2022-36804-poc-exploit

CVE-2022-36804-PoC-Exploit

कुछ हद तक विश्वसनीय PoC एक्सप्लॉइट CVE-2022-36804 (BitBucket क्रिटिकल कमांड इंजेक्शन) के लिए

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
161062 साल पहलेअभी तक समीक्षित नहीं

CVE-2022-36804-PoC-Exploit

CVE-2022-36804 के लिए एक कुछ हद तक विश्वसनीय PoC शोषण (BitBucket क्रिटिकल कमांड इंजेक्शन)। यह हमला आमतौर पर सार्वजनिक रेपो को सक्षम करने की आवश्यकता होती है, हालांकि सत्र कुकीज़ भी इस शोषण के साथ संगत हैं। नोट: इस शोषण में स्वचालित रेपो पहचान शामिल है जो उपयोगी है यदि आप स्वयं खुले रेपो खोजना नहीं चाहते हैं।

स्थापना

git clone https://github.com/BenHays142/CVE-2022-36804-PoC-Exploit.git;
cd CVE-2022-36804-PoC-Exploit
python3 -m pip install -r requirements.txt
python3 main.py [target]

उपयोग

usage: main.py [-h] [--project PROJECT] [--repo REPO] [--skip-auto] [--session SESSION] [--command CMD] server

Exploit BitBucket Instances (< v8.3.1) using CVE-2022-36804. Exploits automagically without any extra parameters, but allows for custom settings as well.

positional arguments:
  server

options:
  -h, --help         show this help message and exit
  --project PROJECT  The name of the project the repository resides in
  --repo REPO        The name of the repository
  --skip-auto        Skip the automatic finding of exploitable repos
  --session SESSION  Value of 'BITBUCKETSESSIONID' cookie, useful if target repo is private
  --command CMD      Command to execute if exploit is successful (Note: getting output isn't reliable so OOB exfil is a must)

संदर्भ

Atlassian सलाह

Atlassian Jira मुद्दा

NIST CVE

टूल डाउनलोड करें