Skip to content

Commit bd8eadb

Browse files
author
jenkins-metasploit
committed
automatic module_metadata_base.json update
1 parent 10d443d commit bd8eadb

File tree

1 file changed

+44
-0
lines changed

1 file changed

+44
-0
lines changed

db/modules_metadata_base.json

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8822,6 +8822,50 @@
88228822
}
88238823
]
88248824
},
8825+
"auxiliary_admin/networking/thinmanager_traversal_upload": {
8826+
"name": "ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload",
8827+
"fullname": "auxiliary/admin/networking/thinmanager_traversal_upload",
8828+
"aliases": [],
8829+
"rank": 300,
8830+
"disclosure_date": "2023-04-05",
8831+
"type": "auxiliary",
8832+
"author": [
8833+
"Michael Heinzl",
8834+
"Tenable"
8835+
],
8836+
"description": "This module exploits a path traversal vulnerability (CVE-2023-27855 ) in ThinManager <= v13.0.1 to upload arbitrary files to the target system.\n\n The affected service listens by default on TCP port 2031 and runs in the context of NT AUTHORITY\\SYSTEM.",
8837+
"references": [
8838+
"CVE-2023-27855 ",
8839+
"URL-https://www.tenable.com/security/research/tra-2023-13",
8840+
"URL-https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640"
8841+
],
8842+
"platform": "",
8843+
"arch": "",
8844+
"rport": 2031,
8845+
"autofilter_ports": [],
8846+
"autofilter_services": [],
8847+
"targets": null,
8848+
"mod_time": "2025-05-15 21:55:58 +0000",
8849+
"path": "/modules/auxiliary/admin/networking/thinmanager_traversal_upload.rb",
8850+
"is_install_path": true,
8851+
"ref_name": "admin/networking/thinmanager_traversal_upload",
8852+
"check": true,
8853+
"post_auth": false,
8854+
"default_credential": false,
8855+
"notes": {
8856+
"Stability": [
8857+
"crash-safe"
8858+
],
8859+
"Reliability": [],
8860+
"SideEffects": [
8861+
"ioc-in-logs",
8862+
"artifacts-on-disk"
8863+
]
8864+
},
8865+
"session_types": false,
8866+
"needs_cleanup": false,
8867+
"actions": []
8868+
},
88258869
"auxiliary_admin/networking/ubiquiti_config": {
88268870
"name": "Ubiquiti Configuration Importer",
88278871
"fullname": "auxiliary/admin/networking/ubiquiti_config",

0 commit comments

Comments
 (0)