This module exploits CVE-2026-88771, a command injection vulnerability present in the ns_monuploadd_err.pl script of Citrix NetScaler ADC and Gateway to deploy a Core Impact Network agent that will run with root privileges. The module will exploit the vulnerability by sending a crafted HTTP POST request the /p/u/doAuthentication.do endpoint with the payload inside the User-Agent header. The result of the HTTP request will determine if the command injection was successful. If the command injection is successful, the module will wait up to 24 hours for agent connection. This is because the appliance runs the ns_monuploadd_err.pl script every 24 hours and the attack has no way to determine the current timelapse for this behaviour. The deployed Core Impact Network agent will run with root privileges.
This module exploits CVE-2026-59310, a directory traversal vulnerability in the Syslog server component of VMware vCenter Server to deploy an Core Impact OSCI agent. The module will use the vulnerability to create a log file inside the /opt/vmware/share/htdocs/configurev2/ directory and then verify the result via a HTTP GET request to the /configurev2 endpoint via the 5480 port with a random filename terminated in the "-syslog.log" string. Then, the module will try to erase the created log file by using the vulnerability again to create a cron file inside the /etc/cron.d/ directory. The cron job will autodelete itself. If the target is vulnerable, the module will deploy an Core Impact OSCI agent with capabilities to execute commands as root. Due to the way the vulnerability is exploited, no command output is possible, so Core Impact OSCI agent terminal commands will be marked as blind.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact network Agent.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact agent with root privileges.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without requiring authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required. Linux agent delivery uses curl because standard Joomla PHP/Apache images commonly include curl without wget. The selected Impact web server must be reachable from the target container.
This module exploits CVE-2026-63077, a pre-authentication unsafe XML deserialization vulnerability in JetBrains TeamCity On-Premises. It registers a synthetic build agent through the agent polling protocol and submits a crafted XML document using the resulting agent session, without requiring TeamCity user credentials. Deserialization of the payload initializes an in-memory HSQLDB data source and uses HSQLDB's SCRIPT functionality to write a temporary JSP payload into the TeamCity ROOT web application. The module requests this JSP to execute an operating-system command as the account running the TeamCity server service. The JSP captures combined standard output and standard error, deletes itself when invoked, and is guarded against repeated execution. The module can verify the vulnerability, identify Linux or Windows targets, execute commands, and deploy an encrypted OSCI agent. It supports HTTP and HTTPS targets, including IPv6 addresses. Agent deployment is implemented for x86-64 Linux and Windows systems. Each command requires three HTTP requests: synthetic-agent registration, delivery of the deserialization payload, and invocation of the generated JSP. Commands are limited to 2026 characters, execution is limited to approximately 10 seconds, and captured output is limited to 1 MiB. Commands are executed with the privileges of the TeamCity server process. The exploit was tested against TeamCity 2025.11.6 on Ubuntu Linux 26.04 LTS and Windows Server 2025 Datacenter. Other vulnerable versions or platforms may also be affected but have not been verified by the engineering team.
This module exploits CVE-2026-63077, a pre-authentication unsafe XML deserialization vulnerability in JetBrains TeamCity On-Premises. It registers a synthetic build agent through the agent polling protocol and submits a crafted XML document using the resulting agent session, without requiring TeamCity user credentials. Deserialization of the payload initializes an in-memory HSQLDB data source and uses HSQLDB's SCRIPT functionality to write a temporary JSP payload into the TeamCity ROOT web application. The module requests this JSP to execute an operating-system command as the account running the TeamCity server service. The JSP captures combined standard output and standard error, deletes itself when invoked, and is guarded against repeated execution. The module can verify the vulnerability, identify Linux or Windows targets, execute commands, and deploy an encrypted OSCI agent. It supports HTTP and HTTPS targets, including IPv6 addresses. Agent deployment is implemented for x86-64 Linux and Windows systems. Each command requires three HTTP requests: synthetic-agent registration, delivery of the deserialization payload, and invocation of the generated JSP. Commands are limited to 2026 characters, execution is limited to approximately 10 seconds, and captured output is limited to 1 MiB. Commands are executed with the privileges of the TeamCity server process. The exploit was tested against TeamCity 2025.11.6 on Ubuntu Linux 26.04 LTS and Windows Server 2025 Datacenter. Other vulnerable versions or platforms may also be affected but have not been verified by the engineering team.
This module exploits CVE-2025-37164, an unauthenticated remote code execution vulnerability in HPE OneView. The module first queries the appliance version endpoint, then validates the vulnerability by sending a benign command to the ID Pools executeCommand REST endpoint. If the target is vulnerable, commands are executed through the same endpoint to deploy an OSCI agent or a classic network agent. The vulnerable endpoint does not return command output, so the OSCI agent is committed as a blind command execution primitive.
This module uses a chain of a REST batch route-confusion combined with a SQL injection vulnerability to deploy a network agent in WordPress Core that will run with the same user privileges than the affected software. The module will use the vulnerability chain and perform the following steps: * Check if the target is vulnerable. If it's not, the attack will stop. * Query the current number of wp_posts rows whose type is oembed_cache. This is saved so cleanup can later verify the run restored the cache count. * Create a random run_token, choose a high fake source_id, and build three unique embed URLs labeled outer, changeset, and dispatch. These are used to create traceable oEmbed cache rows for this run. * Build WordPress [embed]...[/embed] content containing those three URLs, then call union_posts(...) with a forged post row. Afterward, it will query the newest three oembed_cache row IDs and store them as outer_id, changeset_id, and dispatch_id. * Build a customize_changeset JSON payload, use the given administrator credentials (or generate random ones), and construct several fake wp_posts rows: an oEmbed cache row, a changeset row, a draft page, a request/dispatch row, a source post, and a trigger post. * Attempt to replay a privileged WordPress request using the crafted rows (via union_posts(rows, admin_body)) and create the temporary administrator account. It verifies creation either from the response or by counting matching wp_users rows. * Login as the temporary administrator, grab a REST nonce from the dashboard, create a unique plugin slug and secret web token, then call upload_and_activate(...). That helper creates a ZIP containing a temporary PHP plugin, uploads it through the WordPress plugin installer, finds the activation link, and activates it. * Send the necessary OS commands to deploy a CORE Impact agent to the temporary HTTP command endpoint via the run_command(...) function. * Call the plugin's cleanup endpoint using the secret token. The PHP plugin deletes the oEmbed/cache post IDs saved earlier. The script checks for WP2SHELL_CACHE_CLEANUP_COMPLETE. * Builds the REST API plugin path, mark the plugin inactive, then delete it through /wp-json/wp/v2/plugins/ endpoint. The REST response is checked against "deleted": true. * Identifies the current logged-in user, deletes that user with reassignment to user 1, then will check: the temporary username no longer exists, the plugin is no longer referenced in active_plugins, the final oEmbed cache count matches the baseline and the site root still returns HTTP 200.
Pagination
- Page 1
- Next page