projectdiscovery / nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.
https://github.com/projectdiscovery/nuclei
MIT License
8.99k stars 2.57k forks source link

Karaf v4.4.3 Console - Remote Code Execution Exploit #9382

Open whereveryouare666 opened 5 months ago

whereveryouare666 commented 5 months ago

Template for?

CVE N/A

Details:

PoC https://0day.today/exploit/39461 https://www.exploit-db.com/exploits/51895

thefoggiest commented 1 month ago

This template already tests if Karaf is vulnerable to this exploit by looking for web console access and default credentials.