Skip to content

Commit 958ae5b

Browse files
author
jenkins-metasploit
committed
automatic module_metadata_base.json update
1 parent 312d052 commit 958ae5b

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

db/modules_metadata_base.json

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8866,6 +8866,50 @@
88668866
"needs_cleanup": false,
88678867
"actions": []
88688868
},
8869+
"auxiliary_admin/networking/thinmanager_traversal_upload2": {
8870+
"name": "ThinManager Path Traversal (CVE-2023-2917) Arbitrary File Upload",
8871+
"fullname": "auxiliary/admin/networking/thinmanager_traversal_upload2",
8872+
"aliases": [],
8873+
"rank": 300,
8874+
"disclosure_date": "2023-08-17",
8875+
"type": "auxiliary",
8876+
"author": [
8877+
"Michael Heinzl",
8878+
"Tenable"
8879+
],
8880+
"description": "This module exploits a path traversal vulnerability (CVE-2023-2917) in ThinManager <= v13.1.0 to upload arbitrary files to the target system.\n\n The affected service listens by default on TCP port 2031 and runs in the context of NT AUTHORITY\\SYSTEM.",
8881+
"references": [
8882+
"CVE-2023-2917 ",
8883+
"URL-https://www.tenable.com/security/research/tra-2023-28",
8884+
"URL-https://support.rockwellautomation.com/app/answers/answer_view/a_id/1140471"
8885+
],
8886+
"platform": "",
8887+
"arch": "",
8888+
"rport": 2031,
8889+
"autofilter_ports": [],
8890+
"autofilter_services": [],
8891+
"targets": null,
8892+
"mod_time": "2025-05-15 21:55:27 +0000",
8893+
"path": "/modules/auxiliary/admin/networking/thinmanager_traversal_upload2.rb",
8894+
"is_install_path": true,
8895+
"ref_name": "admin/networking/thinmanager_traversal_upload2",
8896+
"check": true,
8897+
"post_auth": false,
8898+
"default_credential": false,
8899+
"notes": {
8900+
"Stability": [
8901+
"crash-safe"
8902+
],
8903+
"Reliability": [],
8904+
"SideEffects": [
8905+
"ioc-in-logs",
8906+
"artifacts-on-disk"
8907+
]
8908+
},
8909+
"session_types": false,
8910+
"needs_cleanup": false,
8911+
"actions": []
8912+
},
88698913
"auxiliary_admin/networking/ubiquiti_config": {
88708914
"name": "Ubiquiti Configuration Importer",
88718915
"fullname": "auxiliary/admin/networking/ubiquiti_config",

0 commit comments

Comments
 (0)