Sploitus

Exploit for CVE-2020-10199_POC-EXP

kitploit · 2026-08-26

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-ZHZYKER-CVE-2020-10199_POC-EXP
الإصدارات المتأثرة <= 3.21.1 يتطلب تسجيل دخول المستخدم ثم توفير csrf و sessionid (يتم نسخهما من المتصفح بعد تسجيل الدخول بنجاح)، ولا يمكن رؤية مخرجات تنفيذ الأوامر حاليًا

# POC

root@kitploit:~
    
    
    +----------------------------------------------------------------------------------------------------------+
    + DES: by zhzyker as https://github.com/zhzyker/exphub                                                     +
    +      CVE-2020-10199 need username & password                                                             +
    +----------------------------------------------------------------------------------------------------------+
    + USE: python3 <filename> <ip> <port> <csrf> <sessionid>                                                   +
    + EXP: python3 cve-2020-10199_poc.py 1.1.1.1 8081 0.9567822851573897 edfca15e-c721-45e2-bdef-e8b3c6364ddb  +
    + VER: Nexus Repository Manager OSS/Pro version <= 3.21.1                                                  +
    +----------------------------------------------------------------------------------------------------------+
    

# EXP

root@kitploit:~
    
    
    +----------------------------------------------------------------------+
    + DES: by zhzyker as https://github.com/zhzyker/exphub                 +
    +      CVE-2020-10199 Nexus 3 remote command execution                 +
    +----------------------------------------------------------------------+
    + USE: python3 <filename> <url> <username> <password>                  +
    + EXP: python3 cve-2020-10199_cmd.py http://127.0.0.1:8081 admin admin +
    + VER: Nexus Repository Manager 3.x OSS / Pro <= 3.21.1                +
    +----------------------------------------------------------------------+