Skip to content

vulcat-v1.1.3

Compare
Choose a tag to compare
@CLincat CLincat released this 05 Sep 04:12
· 17 commits to main since this release

2022.09.05
vulcat-v1.1.3

  • 新增POC
  1. Apache httpd 2.4.48 mod_proxy SSRF (CVE-2021-40438)
  2. Apache httpd 2.4.49 路径遍历 (CVE-2021-41773)
  3. Apache HTTP Server 2.4.50 路径遍历 (CVE-2021-42013)
  4. influxdb 未授权访问 (暂无编号)
  5. jetty 模糊路径信息泄露 (CVE-2021-28164)
  6. jetty Utility Servlets ConcatServlet 双重解码信息泄露 (CVE-2021-28169)
  7. jetty 模糊路径信息泄露 (CVE-2021-34429)
  8. Jupyter 未授权访问 (暂无编号)
  9. mini_httpd 任意文件读取 (CVE-2018-18778)
  10. Nexus Repository Manager 3 远程命令执行 (CVE-2019-7238)
  11. Nexus Repository Manager 3 远程命令执行 (CVE-2020-10199)
  12. Nexus Repository Manager 3 远程命令执行 (CVE-2020-10204)
  13. Nexus Repository Manager 2 yum插件 远程命令执行 (CVE-2019-5475)
  14. Nexus Repository Manager 2 yum插件 二次远程命令执行 (CVE-2019-15588)
  • 新增参数
    --auth: 添加Authorization (如: --auth "Basic YWRtaW46YWRtaW4=")
    --socks4-proxy: socks4代理 (如: --socks4-proxy 127.0.0.1:8080)
    --socks5-proxy: socks5代理 (如: --socks5-proxy 127.0.0.1:8080 或 admin:123456@127.0.0.1:8080)

  • 优化部分POC


  • new POC:
  1. Apache httpd 2.4.48 mod_proxy SSRF (CVE-2021-40438)
  2. Apache httpd 2.4.49 Directory traversal (CVE-2021-41773)
  3. Apache HTTP Server 2.4.50 Directory traversal (CVE-2021-42013)
  4. influxdb unAuthorized (暂无编号)
  5. jetty Disclosure information (CVE-2021-28164)
  6. jetty Utility Servlets ConcatServlet Disclosure information (CVE-2021-28169)
  7. jetty Disclosure information (CVE-2021-34429)
  8. Jupyter unAuthorized (暂无编号)
  9. mini_httpd FileRead (CVE-2018-18778)
  10. Nexus Repository Manager 3 Remote code execution (CVE-2019-7238)
  11. Nexus Repository Manager 3 Remote code execution (CVE-2020-10199)
  12. Nexus Repository Manager 3 Remote code execution (CVE-2020-10204)
  13. Nexus Repository Manager 2 yum Remote code execution (CVE-2019-5475)
  14. Nexus Repository Manager 2 yum Remote code execution (CVE-2019-15588)
  • New parameters:
    --auth: add Authorization (e.g. --auth "Basic YWRtaW46YWRtaW4=")
    --socks4-proxy: socks4 Proxy (e.g. --socks4-proxy 127.0.0.1:8080)
    --socks5-proxy: socks5 Proxy (e.g. --socks5-proxy 127.0.0.1:8080 or admin:123456@127.0.0.1:8080)

  • Optimized partial POC