Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2017-16744 PoC — Tridium Niagara AX Framework和Niagara 4 Framework 路径遍历漏洞

Source
Associated Vulnerability
Title:Tridium Niagara AX Framework和Niagara 4 Framework 路径遍历漏洞 (CVE-2017-16744)
Description:A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.
Description
 Proof of Concept (PoC) for  CVE: 2017-16744 and 2017-16748
Readme
# PoC for CVE-2017-16744 and CVE-2017-16748

* Proof of Concept (PoC)
* CVE: 2017-16744 and 2017-16748
* Date: 09/09/2019
* Exploit Author: GainSec - Jon Gaines
* Vendor Homepage: https://www.tridium.com/
* Version: Affects Tridium Niagara AX Versions: 3.8 and prior as well as Niagara 4 Versions: 4.4 and prior
* Discovered, Reported and PoC'd by Jon Gaines of GainSec & nVisium; Formerly of Stratum Security and Leet Cyber Security

## More Information

 * https://ics-cert.us-cert.gov/advisories/ICSA-18-191-03
 * https://nvd.nist.gov/vuln/detail/CVE-2017-16744
 * https://nvd.nist.gov/vuln/detail/CVE-2017-16748
 * https://vuldb.com/?id.123046

## Prerequisites

Python 3

## Authors

* **Jon Gaines** - *Initial work* - [GainSec](https://gainsec.com)

## License

This project is licensed under the GNU License - see the [LICENSE.md](LICENSE.md) file for details

## Acknowledgments

* https://blog.stratumsecurity.com/2018/09/06/cve-2017-16744-and-cve-2017-16748/
File Snapshot

[4.0K] /data/pocs/074652d3312de6e3aa03386d276b955eccc87e66 ├── [ 34K] LICENSE ├── [ 970] README.md ├── [1.5K] Tridium-PoC-Final-2.py └── [ 478] Tridium-PoC-Final.sh 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →