Sploitus

Exploit for Improper Validation of Specified Type of Input in Servicenow

githubexploit · 2024-07-28

Exploit Code

README18 lines
## https://sploitus.com/exploit?id=FEF11123-CEBF-565E-894E-98A182176FD8
# CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning
CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.

## Resource Vuln Info
https://www.assetnote.io/resources/research/chaining-three-bugs-to-access-all-your-servicenow-data

## Usage
```nuclei -t CVE-2024-4879-Detect-Database-ServiceNow.yaml -l TargetList.txt```

```nuclei -t CVE-2024-4879-Detect-Multiplication-ServiceNow.yaml -l TargetList.txt```

```nuclei -t CVE-2024-5217-Detect-Incomplete-Input-Validation-ServiceNow.yaml -l TargetList.txt```


## Shodan Dork

```server: ServiceNow "200"```