$./CVE-2021-36260.py --rhost 192.168.57.20 --rport 8080 --cmd "ls -l" Execute blind command: $./CVE-2021-36260.py --rhost 192.168.57.20 --rport 8080 --cmd_blind "reboot" $./CVE-2021-36260.py -h [*] Hikvision CVE-2021-36260 [*] PoC by bashis <mcw noemail eu> (2021)...
-[iOS 15.0.1 RCE PoC](https://github.com/jonathandata1/ios_15_rce) -[CVE-2021-36260:海康威视产品命令注入漏洞](https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html) -[CVE-2021-33044、CVE-2021-33045 大华摄像头POC](https://github.com/mcw0/DahuaConsole)...
Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported. - PoC/CVE-2021-36260.py at master · mcw0/PoC
近日,研究人员在海康威视IP摄像机/NVR设备固件中发现一个未认证的远程代码执行漏洞,漏洞CVE编号为CVE-2021-36260。漏洞影响IP摄像头和NVR设备固件,其中包括2021年6月的最新固件以及2006年发布的固件。 攻击者利用该漏洞可以用无限制的root shell来完全控制设备,即使设备的所有者受限于有限的受保护shell(psh)。除了入侵...
CVE-2021-21315-PoC-Node.js组件systeminformation代码注入漏洞 CVE-2021-23132-Joomla! 目录遍历导致 RCE 漏洞EXP|复现文章-原文链接 对ShirneCMS的一次审计思路-反序列化getshell-原文地址-cms地址1-cms地址2 Apache Solr最新版任意文件读取0day|原文地址 KiteCMS的漏洞挖掘之旅(任意文件写入、任意文件读取和反序列化...
name: poc-yaml-hikvision-unauthenticated-rce-cve-2021-36260 manual: true transport: http set: r1: randomLowercase(5) r2: randomLowercase(5) r3: randomLowercase(5) r4: randomLowercase(5) rules: r1: request: cache: true method: PUT
CVE-2021-36260 POC command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands. Exploit Title: Hikvision Web Server ...
靶场系列.md add 施耐德充电桩漏洞挖掘之旅【IOT设备漏洞挖掘 Aug 4, 2021 Repository files navigation README License Penetration_Testing_POC 搜集有关渗透测试中用到的POC、脚本、工具、文章等姿势分享,作为笔记吧,欢迎补充。 请注意所有工具是否有后门或者其他异常行为,建议均在虚拟环境操作。 Penetration_Testing_...
* Update hikvision-unauthenticated-rce-cve-2021-36260.yml Co-authored-by: smile-jpg <55220445+smile-jpg@users.noreply.github.com> Showing1 changed filewith45 additionsand0 deletions. 45pocs/hikvision-unauthenticated-rce-cve-2021-36260.yml...
goby poc or exp,分享goby最新网络安全漏洞检测或利用代码. Contribute to aetkrad/goby_poc development by creating an account on GitHub.