Niflheim World

Welcome to Niflheim !

  • First 5 messages from new users (pre-moderated user) will be checked for flood/spam before being posted on the forum. Users will also be checked for a multi-account.
    If you want to communicate without delay, get a free Huscarl status (how to get - User Groups), or buy premium status (how to buy - Premium status)

PoC for CVE-2020-6207 Remote Code Execution [Fixed] (Missing Authentication Check in SAP Solution Manager)


hacxx

Local User
Bond
Joined
Sep 28, 2020
Messages
1,477
Reaction score
38
NL COIN
4,783
Yesterday i was reading a article in zdnet about a fresh exploit and PoC that allow remote code execution with the possibility to completely automate the exploitation. The PoC is easy to use and it only require some command lines to check if a host is vulnerable or not. If vulnerable it can execute exes.

View the article:

Note: The file is almost equal to the original but there is some fixes. Credits removed, User-Agent in the payload had a tracking code which was removed too.

Download:
 
shape1
shape2
shape3
shape4
shape7
shape8
Top