
Cockpit CMS 0.11.1 Iniezione NoSQL verso Esecuzione di Codice Remoto
Cockpit CMS presenta alcune vulnerabilità NoSQL che possono essere utilizzate per scaricare le informazioni degli utenti. Queste fughe di informazioni possono essere concatenate per modificare le password degli utenti e portare a Esecuzione Remota di Codice sul server.
Una breve descrizione di tutte queste vulnerabilità si trova qui.
┌─[0z09e]─[~/project/CVE-2020-35846]
└──╼ $ python3 exploit.py --help
usage: exploit.py [-h] [--dump_all] URL
_________ __ .__ __ ___________________ ___________
\_ ___ \ ____ ____ | | ________ |__|/ |_ \______ \_ ___ \_ _____/
/ \ \/ / _ \_/ ___\| |/ /\____ \| \ __\ | _/ \ \/ | ___)
\ \___( <_> ) \___| < | |_> > || | | | \ \____|
\______ /\____/ \___ >__|_ \| __/|__||__| |____|_ /\______ /_______ /
\/ \/ \/|__| \/ \/ \/
Cockpit CMS NoSQL Injection to Remote Code Execution : CVE-2020-35846
POC written by : 0z09e (https://github.com/0z09e)
positional arguments:
URL Target URL. Example : http://10.20.30.40/path/to/cockpit
optional arguments:
-h, --help show this help message and exit
--dump_all Dump all the informations about each and every user.(No password will be changed and no shell will be deployed)
URL - L'URL di destinazione in cui è in esecuzione Cockpit CMS.--dump_all - Scarica tutte le informazioni di ogni utente presente sul CMS.Distribuzione di un PHP-WebShell :

Scaricamento delle informazioni degli utenti :
