Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-19911 PoC — FreeSWITCH mod_xml_rpc模块命令注入漏洞

Source
Associated Vulnerability
Title:FreeSWITCH mod_xml_rpc模块命令注入漏洞 (CVE-2018-19911)
Description:FreeSWITCH是美国软件开发者Anthony Minessale所研发的一套免费、开源的通信软件。该软件可用于创建音、视频以及短消息类产品和应用。mod_xml_rpc module是其中的一个支持从Web控制触发API的模块。 FreeSWITCH 1.8.2及之前版本中的mod_xml_rpc模块存在安全漏洞。远程攻击者可通过访问TCP 8080端口借助api/system或txtapi/system(或api/bg_system 或txtapi/bg_system)查询字符串利用该漏洞执行任意
Description
freeswitch all version remote command execute (cve-2018-19911)
Readme

* [EN](https://github.com/iSafeBlue/freeswitch_rce/blob/master/README-en.md) 
File Snapshot

[4.0K] /data/pocs/36807ae665a37d877ba80849a66252ac386a3d62 ├── [4.0K] files │   ├── [345K] 1.png │   ├── [303K] 2.png │   ├── [ 68K] 3.png │   ├── [354K] 4.png │   └── [384K] 5.png ├── [1.1K] freeswitch_rce.py ├── [ 49] rce.html ├── [1.0K] README-en.md └── [ 81] README.md 1 directory, 9 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.