PT-2026-22067 · Netexec · Netexec
Raynlight
·
Publicado
2026-02-26
·
Atualizado
2026-02-26
·
CVE-2026-27884
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NetExec versions prior to 1.5.1
Description
NetExec is a network execution tool. The spider plus module does not properly handle file paths when saving files from SMB shares, specifically failing to account for path traversal characters like
../ in Linux SMB shares. This allows an attacker to craft a filename containing these characters, potentially leading to arbitrary file overwrites or creation during file downloads performed by the spider plus module. The issue is addressed in version 1.5.1.Recommendations
Versions prior to 1.5.1 should be updated to version 1.5.1 or later.
As a workaround, avoid running spider plus with DOWNLOAD=true against targets.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netexec