Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.
Sign upadd citrix path traversal exploit #12816
Conversation
This comment has been minimized.
This comment has been minimized.
|
Hi! Thanks for this. We'll be making some final changes to the module and landing with #12813 as the exploit's |
Bad habit!
This comment has been minimized.
This comment has been minimized.
|
I forgot about this, sorry: metasploit-framework/modules/auxiliary/gather/pulse_secure_file_disclosure.rb Lines 107 to 111 in 0359a79 I'll add a decent default. |
Just the comment.
This comment has been minimized.
This comment has been minimized.
Release NotesThis adds an exploit for CVE-2019-19781, a directory traversal vulnerability in Citrix ADC (NetScaler) that can be leveraged to execute an arbitrary command payload. |
This comment has been minimized.
This comment has been minimized.
|
@mekhalleh: The exploit has landed. Please review the commits I've added. I hope the changes are positive, and I apologize that I gave you such short notice on this. Thank you! |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
secprentice
commented
Jan 20, 2020
•
|
I am trying to use this exploit but
I can however use
|
This comment has been minimized.
This comment has been minimized.
|
That is an entirely different module. |
This comment has been minimized.
This comment has been minimized.
secprentice
commented
Jan 21, 2020
|
I must be missing something deathly obvious. Thanks for getting back to me, I will try some more to see what I am missing. |
This comment has been minimized.
This comment has been minimized.
|
The one you want is |
This comment has been minimized.
This comment has been minimized.
secprentice
commented
Jan 21, 2020
|
That helps a lot. A definite misunderstanding on my part. Thank you for the great module. |
mekhalleh commentedJan 12, 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Verification
List the steps needed to make sure this thing works
msfconsole