Plugman X
PluginManager is a simple plugin manager. The problem with this plugin is that it allows you to download plugins from unofficial sites.
PluginManager is a simple plugin manager. The problem with this plugin is that it allows you to download plugins from unofficial sites.
The exploit is based on using the /plugman download command to download a malicious plugin to compromise the server.
To perform this exploit, the PluginManager /plugman download command must be enabled, then enter the following:
In this example, a malicious test plugin created by me is attached. Load the plugin without restarting the server Check that the plugin has loaded correctly Commands can now be executed remotely using the #rce command. In this example I use a command to open the notepad of my PC where the server is hosted.Download the malicious plugin
$
Load the infected plugin
$
Test the infected plugin
$
Run a command on the server operating system
$
This plugin is vulnerable in all versions to date.
You can download a server with everything you need to test the exploit locally on your PC from this link.