Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
OTRS-4.0.1-6.0.1-Remote-Command-Execution — CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user. | Kitploit
Ferramentas/GitHubGitHub/smarttfoxx/otrs-4.0.1-6.0.1-remote-command-execution
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubsmarttfoxx/otrs-4.0.1-6.0.1-remote-command-execution

OTRS-4.0.1-6.0.1-Remote-Command-Execution

Ver Repositório

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →

Sobre

há 1 anoAinda não revisado

CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.

Compartilhar

OTRS-4.0.1-6.0.1 Execução Remota de Comandos

Este exploit foi desenvolvido com base em https://www.exploit-db.com/exploits/43853 Ele realizará a autenticação no painel do OTRS e fornecerá um reverse shell.

Uso: python3 CVE-2017-16921.py

CVE-2017-16921: No OTRS 6.0.x até e incluindo 6.0.1, OTRS 5.0.x até e incluindo 5.0.24, e OTRS 4.0.x até e incluindo 4.0.26, um atacante que esteja logado no OTRS como agente pode manipular parâmetros de formulário (relacionados ao PGP) e executar comandos arbitrários do shell com as permissões do usuário do OTRS ou do servidor web.

Créditos a Hex_26 pela função de recuperação do ChallengeToken e a Bæln0rn pelo exploit inicial.

Baixar ferramenta