OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-38751 affecting OpenSTAManager <= 2.10. It contains two files: a README describing the vulnerability and usage, and the main exploit script `cve-2026-38751.py`. The exploit targets the application's module update mechanism and requires valid credentials. Its workflow is: generate a malicious ZIP module (`update.zip`) containing `run/MODULE` and a PHP webshell `run/evil.php`; authenticate to `/index.php?op=login`; enable updates through `/ajax.php?a=check_module_updates_settings`; upload the ZIP to `/modules/aggiornamenti/upload_modules.php`; then verify remote code execution by requesting `/modules/run/evil.php?cmd=id`. If operator-supplied `--lhost` and `--lport` are provided, it uses the webshell to execute a bash reverse shell command back to the attacker. The exploit is operational rather than a simple detector because it performs end-to-end exploitation and includes a usable payload. Notable code quality issue: the script references `count(10)` in `main()` without importing or defining `count`, so as written it would fail during the verification loop unless corrected (likely intended to be `range(10)` or `itertools.count`). Despite that bug, the exploit's intended capability and target endpoints are clear: authenticated arbitrary file upload leading to PHP-based RCE in the web application context.
Repository contains a single Python exploit script (exploit.py) and a README. The script is a standalone authenticated web RCE exploit targeting OpenSTAManager 2.10 (CVE-2026-38751). Its workflow is: validate target URL, authenticate with supplied credentials, enable module updates through an AJAX endpoint, generate an in-memory ZIP archive containing a malicious module descriptor and PHP webshell, upload that ZIP through the module update upload endpoint, verify the shell at /modules/shell/shell.php, then provide post-exploitation options. The post-exploitation capability includes direct command execution via the webshell using GET parameter c, an interactive shell mode, and reverse-shell triggering using common bash/python/netcat one-liners. The exploit is operational rather than a simple detector because it delivers a working payload and performs end-to-end exploitation. Repository structure is minimal and purpose-built: README documents usage and attack flow, while exploit.py implements session handling, URL joining, login checks, update enablement, ZIP creation, upload, verification, execution, and cleanup logic.
This repository is a small standalone Python exploit for CVE-2026-38751 affecting OpenSTAManager <= 2.10.x. It is not part of a larger exploitation framework. The repository contains four files: a MIT LICENSE, a short README with usage examples, requirements.txt listing requests, and the main exploit implementation in exploit.py. The exploit targets an authenticated remote code execution condition in OpenSTAManager’s module update workflow. Its core logic is: create an HTTP session, authenticate with supplied credentials, enable module updates through an authenticated AJAX settings endpoint, build a malicious ZIP archive in memory, upload that archive to the vulnerable module upload endpoint, verify that the PHP webshell was extracted to a predictable web-accessible location, and then use that shell for command execution. The malicious ZIP contains two files: shell/MODULE, which is required by OpenSTAManager to accept the archive as a valid module, and shell/shell.php, a minimal PHP webshell that executes commands passed via the c GET parameter using system(). The exploit comments indicate the shell is expected to land at /modules/shell/shell.php after extraction. Capabilities are beyond simple detection: it performs full authenticated exploitation and post-exploitation command execution. It supports three practical modes: default proof-of-execution mode running commands like id/hostname/pwd, an interactive webshell mode for repeated command execution, and a reverse shell mode that triggers a bash callback to an attacker-controlled host and port. The script also includes cleanup support to remove the deployed shell unless the operator disables cleanup. Operationally, the exploit relies on valid credentials and on the target exposing the documented OpenSTAManager endpoints. It also assumes the uploaded ZIP is extracted under the modules directory and that the resulting PHP file is executable by the web server. Overall, this is a functional authenticated web RCE exploit with a hardcoded but effective PHP payload and optional reverse shell behavior, making it an operational PoC rather than a mere scanner or detection script.
This is a small standalone Rust exploit repository for CVE-2026-38751 targeting OpenSTAManager <= 2.10. The repository contains 5 files total, with the main logic in `src/main.rs`, package metadata in `Cargo.toml`/`Cargo.lock`, and usage documentation in `README.md`. The exploit is a real authenticated RCE PoC, not just a detector. It logs into the target application using supplied credentials, enables update functionality, generates an in-memory ZIP archive containing a malicious module descriptor (`shell/MODULE`) and a PHP webshell (`shell/shell.php`), uploads that archive through the application's module/update mechanism, verifies successful deployment, and then provides post-exploitation options. Core capabilities observed in code and documentation: - Authenticated login with cookie-backed session handling via reqwest. - Update-setting activation through `/ajax.php?a=check_module_updates_settings`. - Arbitrary file upload by packaging a fake module ZIP. - Webshell deployment at `/modules/shell/shell.php` using `system($_GET["c"])` for command execution. - Verification by issuing a test command after upload. - Interactive webshell mode for repeated command execution. - Reverse shell support with multiple fallback payload styles (bash, python3, python, base64, nc, mkfifo per README). - Cleanup support to remove the uploaded backdoor unless `--no-cleanup` is specified. The exploit uses command-line arguments for target URL, username, password, interactive mode, cleanup control, and reverse-shell listener parameters (`--lhost`, `--lport`). Because the payload is fixed/basic rather than highly modular, the maturity is best classified as OPERATIONAL rather than WEAPONIZED. Fingerprintable targets and artifacts include the login endpoints, the update-settings AJAX endpoint, the session-check controller path, and the deployed shell path under `/modules/shell/shell.php`. The exploit is aimed at web application compromise over HTTP(S), with optional outbound TCP reverse-shell callbacks from the victim to the attacker.
Repository contains a single Python exploit script (poc.py) and a short README describing the same attack flow. The exploit targets OpenSTAManager <= 2.10 and claims CVE-2026-38751: an authenticated arbitrary file upload in the module update mechanism leading to remote code execution. The script logs into the target using provided credentials, enables updates through /ajax.php?a=check_module_updates_settings, builds a malicious ZIP archive named poc.zip containing a MODULE descriptor and a PHP webshell, uploads it to /modules/aggiornamenti/upload_modules.php, then verifies execution by calling /modules/shell/shell.php?c=id. If successful, it provides command execution through the c parameter, supports an interactive shell mode, runs sample commands like whoami and pwd, and can remove the shell afterward using rm on /var/www/html/modules/shell/shell.php. Overall, this is a functional authenticated web RCE exploit rather than a detector, with a hardcoded but effective payload and straightforward operational flow.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.