{"repo":"joshuavanderpoll/CVE-2021-3129","free":true,"listed":false,"github":"https://github.com/joshuavanderpoll/CVE-2021-3129","clone":"git clone https://github.com/joshuavanderpoll/CVE-2021-3129.git","description":"Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)","language":"Python","stars":150,"topics":["cve","cve-2021-3129","laravel","python","security-tools","vulnerability","exploit","scanner","exploits","pentest-tool"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Remote Code Execution: Laravel (CVE-2021-3129) 📜 Description This script is designed to exploit the Remote Code Execution (RCE) vulnerability identified in several Laravel versions, known as CVE-2021-3129. By leveraging this vulnerability, the script allows users to write and execute commands on a target website running a vulnerable Laravel instance, provided that the \"APP DEBUG\" configuration is set to \"true\" in the \".env\" file. Thanks everyone for all the GitHub stars! ❤️ Really appreciate the support! 🚀 📚 Table of Contents - 📜 Description - 🛠️ Installation - ⚙️ Usage - 🐋 Docker POC - 💻 Example - 🩹 Patch options - 🕵🏼 References - 📢 Disclaimer 🛠️ Installation [!NOTE] To ensure a clean and isolated environment for the project dependencies, it's recommended to use Python's venv module. OSX/Linux Windows ⚙️ Usage 🐋 Docker POC 💻 Example 🩹 Patch options - env (Updates the .env file to set APP DEBUG to false) - index (Injects code into index.php which prevents access to \"/ ignition/execute-solution\") - private (Same as the index option, but allows specific header to access \" ignition/execute-solution\") 🕵🏼 References - https://github.com/ambionics/phpggc 📢 Disclaimer This tool is provided for educational and research purposes only. The creator assumes no responsibility for any misuse or damage caused by the tool.","default_branch":null,"files":null,"tree":[],"storefront":"/r/joshuavanderpoll","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/joshuavanderpoll/CVE-2021-3129/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}