
सिस्को CVE-2020-3452 के लिए सिर्फ प्रूफ ऑफ कॉन्सेप्ट। बाहरी या आंतरिक फ़ाइल बेस का उपयोग करते हुए।
केवल शैक्षणिक उद्देश्य के लिए!
बस एक बुनियादी शोषण जो CISCO ASA/FTD उपकरणों की वेब निर्देशिका में उपलब्ध मानक फ़ाइलों को सूचीबद्ध करने के लिए CVE-2020-3452 का दुरुपयोग करता है।
डिफ़ॉल्ट रूप से यह Metasploit Framework में CVE-2018-0296 के नमूना आउटपुट से निर्मित फ़ाइल सूची का उपयोग करता है (https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/scanner/http/cisco_directory_traversal.md)।
Usage: cve-2020-3452.sh <target ip/hostname> <optional_file_name>.txt
Example#1: cve-2020-3452.sh mytarget.com
Example#2: cve-2020-3452.sh mytarget.com cisco_asa_file_list.txt
Files that are downloaded will be in the newly created 'cisco_asa_files' directory