目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-46811 PoC — SUSE Manager 访问控制错误漏洞

来源
关联漏洞
标题: SUSE Manager 访问控制错误漏洞 (CVE-2025-46811)
Description:SUSE Manager是德国SUSE公司的一套Linux服务器管理系统。该系统提供自动化软件管理、系统配置和监控等功能。 SUSE Manager存在访问控制错误漏洞,该漏洞源于关键功能缺少身份验证,可能导致通过websocket执行任意命令。
Description
CVE-2025-46811
介绍
<h1 align="center">SUSE Manager Exploit Toolkit</h1>
<div align="center">
  <strong>CVE-CVE-2025-46811 Scanner & Exploiter</strong><br/>
  <img src="https://img.shields.io/badge/Python-3.8+-blue.svg" alt="Python"/>
  <img src="https://img.shields.io/badge/License-MIT-green.svg" alt="License"/>
</div>

<h2>🚀 Features</h2>
<ul>
  <li>Multi-threaded vulnerability scanning</li>
  <li>Interactive root shell via WebSocket</li>
  <li>Single command execution mode</li>
  <li>Colored debug output</li>
  <li>Batch processing of targets</li>
</ul>

<h2>📦 Installation</h2>
<pre><code>git clone https://github.com/yourusername/suse-manager-exploit.git
cd suse-manager-exploit
pip install -r requirements.txt</code></pre>

<h2>🛠 Usage</h2>
<h3>Scan Mode</h3>
<pre><code>python3 exploit.py scan -i targets.txt -o vulnerable.txt --debug</code></pre>

<h3>Exploit Mode</h3>
<pre><code># Single command
python3 exploit.py exploit 10.0.0.5 -c "cat /etc/passwd"

# Interactive shell
python3 exploit.py exploit vulnerable.com --debug</code></pre>

<h2>🎯 Screenshot</h2>
<img src="screenshot.png" alt="Interactive Shell Demo" width="600"/>

<h2>⚙ Technical Details</h2>
<table>
  <tr>
    <th>Component</th>
    <th>Description</th>
  </tr>
  <tr>
    <td>WebSocket Endpoint</td>
    <td><code>/rhn/websocket/minion/remote-commands</code></td>
  </tr>
  <tr>
    <td>Vulnerability Check</td>
    <td>Verifies root command execution via <code>id</code></td>
  </tr>
  <tr>
    <td>SSL Handling</td>
    <td>Bypasses certificate verification</td>
  </tr>
</table>

<h2>⚠ Disclaimer</h2>
<p><em>This tool is for authorized penetration testing and educational purposes only. Usage against systems without prior permission is illegal.</em></p>

<h2>📜 License</h2>
<p>MIT - Copyright (c) 2023</p>
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →