Exploit for CVE-2022-24112 (RCE in Apache APISIX)
Copy link to “Exploit for CVE-2022-24112 (RCE in Apache APISIX)”Sniper can now exploit a Remote Code Execution vulnerability in the Apache APISIX API Gateway server (CVE-2022-24112).
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
Sniper can now exploit a Remote Code Execution vulnerability in the Apache APISIX API Gateway server (CVE-2022-24112).
Sniper can now exploit a Remote Code Execution vulnerability in the htmlawed module from GLPI (CVE-2022-35914).
When using our Network Scanner (in any mode), you will now get all the ports, not just the open ones. The goal is to have a better view of the target.
Sniper can now exploit a Remote Code Execution vulnerability affecting the web-based management interface of Cisco Small Business RV Series Routers (CVE-2021-1472).
You can now get notified if a scan doesn't have one or more statuses. You can do this by checking the negation checkbox when creating a new notification.
Our Password Auditor will automatically scan for default credentials based on the service or application found.
We've added the option to schedule a task once per year.
Overwrite the default maximum time that the Website Scanner is allowed to run (24h). The minimum is 30 minutes if you want to get faster results.
Sniper can now exploit a Remote Code Execution vulnerability affecting pfBlockerNG packages (CVE-2022-31814).
We have updated the VPN Profile Page with a much more efficient design. You can start your Internal Assessments faster with the easier deployment of VPN Agents, batch testing multiple VPN Profiles, and having all the details at a glance with the new slide-over (such as assigned Workspaces or OpenVPN Logs).
Sniper can now exploit a Server Side Request Forgery vulnerability affecting the Fusion Builder WordPress plugin, used in the well known Avada Wordpress theme (CVE-2022-1386).
Sniper can now exploit a Remote Code Execution vulnerability affecting EJS (Embedded JavaScript templates) Node.js package (CVE-2022-29078).
In addition to the existing attack type, Dictionary, we've added a new one. Password Spray will try for every password every username in the wordlist, before moving on to the next password. This helps to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.
You can now use our Sniper tool to create client-side attacks. Generate a 'malicious' file (doc, docm, xls, xlsm) containing obfuscated VBA and send it to your victim user. Once they open and enable the macros, Sniper runs all the extractors on their machine to gather evidence of the successful attack. This approach does not use any exploits.
We've replaced the old Dashboard page with a new, beautiful page. Now you can view the trend of vulnerabilities for the current workspace on the last 14 days, see at a glance the whole picture of the attack surface for the current workspace and more.
Network Scanner can now detect if a Zoho ManageEngine ADAudit Plus server is vulnerable to XML External Entity Injection (CVE-2022-28219).
Sniper can now exploit an Authentication Bypass vulnerability affecting Fortinet FortiOS, FortiProxy and FortiSwitchManager (CVE-2022-40684).
Password Auditor can now discover the Docker API with no authentication configured.
We've created the Pentest-Tools.com Vulnerability & Exploit Database, which contains the list of vulnerabilities that can be detected and the exploits that are currently available in the platform.
Sniper can now exploit a Remote Code Execution vulnerability affecting Atlassian Bitbucket (CVE-2022-36804).