
CVE-2023-20273 एक्सप्लॉइट पीओसी
CVE-2023-20273 शोषण PoC
usage: exploit.py [-h] -t URL -u Username -p Password (-c Command | -r) [-dest Outfile] [-www | -tcp | -null] [-ip LocalIP] [-port LocalPort] [-fs filesystem] [-path filepath] [-operation operation_type] [-v] [-q]
CVE-2023-20273 Exploit PoC
options:
-h, --help show this help message and exit
Target options:
[Mandatory] Target arguments
-t URL, --url URL Target Cisco URL (eg https://192.168.1.1 or http://192.168.2.2:8080)
-u Username, --user Username Cisco webui user name
-p Password, --pass Password Cisco webui user pass
Exploit mode:
[Mandatory] Exec command or reverse shell
-c Command Command to run
-r Reverse shell (requires -ip and -port)
Output Options:
[Optional] Command output options
-dest Outfile [-r | -www | -tcp] destination file (default: random)
-www [Default] Attempt to retrieve output via target web server
-tcp [Not implemented] Attempt to send output to a TCP listener (requires -ip and -port)
-null Do not attempt to get command output
Callback Options:
For reverse shell or command output
-ip LocalIP Local IP for reverse shell/command output
-port LocalPort Local port for reverse shell/command output
Exploit options:
[Not implemented] Exploit modifiers
-fs filesystem Filesystem on target for exploit staging (default: flash)
-path filepath Filepath on target filesystem for exploit staging (default: shellsmoke)
-operation operation_type Install operation type (not currently implemented) (default: SMU)
Verbosity control:
-v Verbose output
-q Suppress Banner
विकल्प: -h, --help यह सहायता संदेश दिखाएं और बाहर निकलें
लक्ष्य विकल्प: [अनिवार्य] लक्ष्य तर्क
-t URL, --url URL लक्ष्य Cisco URL (eg https://192.168.1.1 or http://192.168.2.2:8080) -u Username, --user Username Cisco webui उपयोगकर्ता नाम -p Password, --pass Password Cisco webui उपयोगकर्ता पासवर्ड
शोषण मोड: [अनिवार्य] कमांड निष्पादित करें या रिवर्स शेल
-c Command चलाने के लिए कमांड -r रिवर्स शेल (-ip और -port आवश्यक)
आउटपुट विकल्प: [वैकल्पिक] कमांड आउटपुट विकल्प
-dest Outfile [-r | -www | -tcp] गंतव्य फ़ाइल (डिफ़ॉल्ट: यादृच्छिक) -www [डिफ़ॉल्ट] लक्ष्य वेब सर्वर के माध्यम से आउटपुट प्राप्त करने का प्रयास करें -tcp [लागू नहीं] TCP लिसनर पर आउटपुट भेजने का प्रयास करें (-ip और -port आवश्यक) -null कमांड आउटपुट प्राप्त करने का प्रयास न करें
कॉलबैक विकल्प: रिवर्स शेल या कमांड आउटपुट के लिए
-ip LocalIP रिवर्स शेल/कमांड आउटपुट के लिए स्थानीय IP -port LocalPort रिवर्स शेल/कमांड आउटपुट के लिए स्थानीय पोर्ट
शोषण विकल्प: [लागू नहीं] शोषण संशोधक
-fs filesystem लक्ष्य पर शोषण स्टेजिंग के लिए फ़ाइलसिस्टम (डिफ़ॉल्ट: flash) -path filepath लक्ष्य फ़ाइलसिस्टम पर शोषण स्टेजिंग के लिए फ़ाइलपथ (डिफ़ॉल्ट: shellsmoke) -operation operation_type इंस्टॉल ऑपरेशन प्रकार (वर्तमान में लागू नहीं) (डिफ़ॉल्ट: SMU)
वर्बोसिटी नियंत्रण: -v विस्तृत आउटपुट -q बैनर दबाएं