Sploitus

Exploit for Server-Side Request Forgery in Microsoft

githubexploit · 2021-03-05

Exploit Code

README2 lines
## https://sploitus.com/exploit?id=37EE4A49-AEF7-5A71-AC1C-4B55CB94DD92
It is an offensive tool for Microsoft Exchange server vulnerability exploitation. The tool targets the "proxylogon" group of vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065), which are related to authentication bypass and remote code execution. The probable entry point is the PowerShell script. Not specified. The tool is designed to detect webshells dropped on Microsoft Exchange servers. Preconditions include the presence of the mentioned vulnerabilities, and the expected impact is the detection of webshells.