黑客、渗透测试和网络安全工具,武装您的安全武器库!
基于Python的ZeroShell 3.9.0远程命令注入概念验证利用,通过错误处理的HTTP参数实现未认证的OS命令执行。
发现我们社区最常用的工具。
探索所有工具
浏览我们的工具集合
ZeroShell 3.9.0 远程命令注入
$ sudo python ZeroShell_RCE.py -u <Base_Host>
参考资料:
https://www.exploit-db.com/exploits/49862
https://packetstormsecurity.com/files/162561/ZeroShell-3.9.0-Remote-Command-Execution.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12725