Skip to content

It is a nmap script for GravCMS vulnerability (CVE-2021-21425)

Notifications You must be signed in to change notification settings

frknktlca/GravCMS_Nmap_Script

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

GravCMS_Nmap_Script

It is a nmap script for GravCMS vulnerability (CVE-2021-21425)

USAGE

-- nmap -p443 --script grav_cms.nse

-- PORT STATE SERVICE

-- 443/tcp open https

-- | grav_cms:

-- | VULNERABLE:

-- | GravCMS (CVE-2021-21425)

-- | State: VULNERABLE (Exploitable)

-- | IDs: CVE:CVE-2021-21425

-- | GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution

-- | Disclosure date: 2021-03-19

-- | References:

-- | https://pentest.blog/unexpected-journey-7-gravcms-unauthenticated-arbitrary-yaml-write-update-leads-to-code-execution/

-- |_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21425

About

It is a nmap script for GravCMS vulnerability (CVE-2021-21425)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages