module

ManageEngine OpManager and Social IT Arbitrary File Upload

Disclosed
2014-09-27
Created
2018-05-30

Description

This module exploits a file upload vulnerability in ManageEngine OpManager and Social IT.
The vulnerability exists in the FileCollector servlet which accepts unauthenticated
file uploads. This module has been tested successfully on OpManager v8.8 - v11.3 and on
version 11.0 of SocialIT for Windows and Linux.

Author

Pedro Ribeiro pedrib@gmail.com

Platform

Java

Architectures

java

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/multi/http/opmanager_socialit_file_upload
msf exploit(opmanager_socialit_file_upload) > show targets
...targets...
msf exploit(opmanager_socialit_file_upload) > set TARGET < target-id >
msf exploit(opmanager_socialit_file_upload) > show options
...show and set options...
msf exploit(opmanager_socialit_file_upload) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.