Overview
This section covers POCs for various other systems including VMware vCenter, Atlassian Confluence, GitLab, F5 BIG-IP, ThinkPHP, Fortinet, Microsoft products, and more.VMware
vCenter RCE vulnerabilities
Confluence
OGNL injection RCE
GitLab
ExifTool RCE
F5 BIG-IP
TMUI & iControl RCE
ThinkPHP
PHP framework RCE
Microsoft
Exchange & SMB vulns
Fastjson
Java JSON RCE
JBoss
Deserialization RCE
PHPUnit
PHP testing RCE
VMware vCenter
CVE-2021-21985 - vCenter RCE
CVE-2021-21985
| Type | Remote Code Execution |
| Affected Product | VMware vCenter Server |
| Discovery Date | May 2021 |
| CVSS Score | 9.8 (Critical) |
pocs_go/VMware/vCenter/CVE_2021_21985.go
CVE-2022-22954 - VMware Workspace ONE RCE
CVE-2022-22954
| Type | Remote Code Execution (SSTI) |
| Affected Product | VMware Workspace ONE Access, Identity Manager |
| Discovery Date | April 2022 |
| CVSS Score | 9.8 (Critical) |
pocs_go/VMware/vCenter/CVE-2022-22954.go
CVE-2022-22972 - Authentication Bypass
CVE-2022-22972
| Type | Authentication Bypass |
| Affected Product | VMware Workspace ONE Access, Identity Manager |
| Discovery Date | May 2022 |
| CVSS Score | 9.8 (Critical) |
pocs_go/VMware/vCenter/CVE_2022_22972.go
Atlassian Confluence
CVE-2021-26084 - OGNL Injection RCE
CVE-2021-26084
| Type | Remote Code Execution (OGNL Injection) |
| Affected Product | Atlassian Confluence Server/Data Center |
| Discovery Date | August 2021 |
| CVSS Score | 9.8 (Critical) |
pocs_go/confluence/CVE_2021_26084.go
CVE-2021-26085
CVE-2021-26085
| Type | Confluence Vulnerability |
| Affected Product | Atlassian Confluence |
| Discovery Date | August 2021 |
pocs_go/confluence/CVE-2021-26085.go
CVE-2022-26134 - OGNL Injection RCE
CVE-2022-26134
| Type | Remote Code Execution |
| Affected Product | Atlassian Confluence Server/Data Center |
| Discovery Date | June 2022 |
| CVSS Score | 9.8 (Critical) |
pocs_go/confluence/CVE_2022_26134.go
CVE-2022-26318
CVE-2022-26318
| Type | Confluence Vulnerability |
| Affected Product | Atlassian Confluence |
| Discovery Date | 2022 |
pocs_go/confluence/CVE_2022_26318.go
GitLab
CVE-2021-22205 - ExifTool RCE
CVE-2021-22205
| Type | Remote Code Execution |
| Affected Product | GitLab CE/EE |
| Discovery Date | April 2021 |
| CVSS Score | 10.0 (Critical) |
- Upload crafted image file
- ExifTool processes metadata
- Arbitrary command execution
pocs_go/gitlab/CVE_2021_22205.go
CVE-2022-2185
CVE-2022-2185
| Type | GitLab Vulnerability |
| Affected Product | GitLab |
| Discovery Date | June 2022 |
pocs_go/gitlab/CVE-2022-2185.go
F5 BIG-IP
CVE-2020-5902 - TMUI RCE
CVE-2020-5902
| Type | Remote Code Execution |
| Affected Product | F5 BIG-IP |
| Discovery Date | July 2020 |
| CVSS Score | 9.8 (Critical) |
pocs_go/f5/CVE_2020_5902.go
CVE-2021-22986 - iControl REST RCE
CVE-2021-22986
| Type | Remote Code Execution |
| Affected Product | F5 BIG-IP iControl REST |
| Discovery Date | March 2021 |
| CVSS Score | 9.8 (Critical) |
pocs_go/f5/CVE_2021_22986.go
CVE-2022-1388 - Authentication Bypass RCE
CVE-2022-1388
| Type | Authentication Bypass → RCE |
| Affected Product | F5 BIG-IP |
| Discovery Date | May 2022 |
| CVSS Score | 9.8 (Critical) |
pocs_go/f5/CVE_2022_1388.go
ThinkPHP
CVE-2019-9082
CVE-2019-9082
| Type | Remote Code Execution |
| Affected Versions | < 3.2.4 |
| Discovery Date | February 2019 |
pocs_go/ThinkPHP/check.go
CVE-2018-20062
CVE-2018-20062
| Type | Remote Code Execution |
| Affected Versions | 5.0.23 and earlier, 5.1.31 and earlier |
| Discovery Date | December 2018 |
| CVSS Score | 9.8 (Critical) |
pocs_go/ThinkPHP/check.go
Fastjson
VER-1262 - Autotype RCE
Fastjson VER-1262
| Type | Remote Code Execution |
| Affected Versions | ≤ 1.2.62 |
| Issue | Autotype Deserialization |
pocs_go/fastjson/check.go
JBoss
CVE-2017-12149 - Deserialization RCE
CVE-2017-12149
| Type | Deserialization RCE |
| Affected Versions | JBoss AS 5.x/6.x |
| Discovery Date | August 2017 |
| CVSS Score | 8.1 (High) |
pocs_go/jboss/CVE_2017_12149.go
PHPUnit
CVE-2017-9841 - RCE
CVE-2017-9841
| Type | Remote Code Execution |
| Affected Versions | 4.x < 4.8.28, 5.x < 5.6.3 |
| Discovery Date | June 2017 |
| CVSS Score | 9.8 (Critical) |
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Exploitation:
pocs_go/phpunit/CVE_2017_9841.go
Microsoft Products
CVE-2020-0796 - SMBGhost
CVE-2020-0796 (SMBGhost)
| Type | Remote Code Execution |
| Affected Product | Windows 10, Windows Server 2019 |
| Discovery Date | March 2020 |
| CVSS Score | 10.0 (Critical) |
pocs_go/ms/CVE-2020-0796.go
CVE-2021-26855 - ProxyLogon
CVE-2021-26855 (ProxyLogon)
| Type | SSRF → Authentication Bypass → RCE |
| Affected Product | Microsoft Exchange Server |
| Discovery Date | March 2021 |
| CVSS Score | 9.8 (Critical) |
pocs_go/ms/CVE_2021_26855.gopocs_go/ms/exchange/proxylogon.gopocs_go/ms/exchange/chkproxyshell.go
CVE-2018-14847 - MikroTik RouterOS
CVE-2018-14847
| Type | Directory Traversal |
| Affected Product | MikroTik RouterOS |
| Discovery Date | July 2018 |
pocs_go/ms/CVE_2018_14847.go
Fortinet
CVE-2018-13380 - FortiOS SSL VPN
CVE-2018-13380
| Type | Path Traversal / Credential Disclosure |
| Affected Product | Fortinet FortiOS SSL VPN |
| Discovery Date | May 2019 |
| CVSS Score | 9.8 (Critical) |
pocs_go/CVE-2018-13380.go
Open Management Infrastructure
CVE-2021-38647 - OMI RCE
CVE-2021-38647
| Type | Remote Code Execution |
| Affected Product | Open Management Infrastructure (OMI) |
| Discovery Date | September 2021 |
| CVSS Score | 9.8 (Critical) |
pocs_go/CVE-2021-38647.go
Zabbix
CVE-2022-23131 - Authentication Bypass
CVE-2022-23131
| Type | Authentication Bypass |
| Affected Product | Zabbix |
| Discovery Date | January 2022 |
pocs_go/zabbix/CVE-2022-23131.go
Chinese Software Systems
scan4all also includes POCs for various Chinese software systems commonly used in China:Seeyon OA
Seeyon OA
System: Seeyon Office AutomationLocation:
pocs_go/seeyon/Description: Multiple vulnerabilities in Seeyon OA systemTongda OA
Tongda OA
System: Tongda Office AutomationLocation:
pocs_go/tongda/Description: Multiple vulnerabilities in Tongda OA systemLandray OA
Landray OA
System: Landray EKPCVE: Landray_RCELocation:
pocs_go/landray/Landray_RCE.goZentao
Zentao
System: Zentao Project ManagementLocation:
pocs_go/zentao/MCMS
MCMS
System: MCMS Content ManagementVulnerability: Front Desk SQL InjectionLocation:
pocs_go/mcms/Front_Desk_sqlinject.goSunlogin
Sunlogin
System: Sunlogin Remote ControlLocation:
pocs_go/sunlogin/