Sploitus

Exploit for CVE-2005-2006 CVE-2005-2006 CVE-2010-0738

gitee · 2018-08-06

Exploit Code

MARKDOWN2 lines
## https://sploitus.com/exploit?id=D3707910-04AE-5224-86A1-D839A3358200
This is an open-source application server attack toolkit called clusterd. It automates the fingerprinting, reconnaissance, and exploitation phases of an application server attack. The toolkit currently supports six different application server platforms, including JBoss, ColdFusion, and WebLogic. It has various features such as dumping deployed WARs, fetching host OS information, and exploiting vulnerabilities like verb tampering (CVE-2010-0738) and credential/path disclosure (CVE-2005-2006). The toolkit uses a fingerprinting engine to discover what service is listening on a remote system and run various fingerprint tests against it. It also has a deployer module that loads a specific platform's deployers and iterates through fingerprints to find one to deploy to. The toolkit can be used to exploit vulnerabilities in application servers, but it should be used responsibly and in accordance with applicable laws and regulations.