Sonatype Nexus Repository Manager
Discovery
curl -I http://TARGET:8081/
curl http://TARGET:8081/robots.txt
curl http://TARGET:8081/service/rest/swagger.json
curl http://TARGET:8081/service/rest/v1/repositoriesServer: Nexus/3.x.x-xx (OSS)
Nexus Repository Manager
/repository/
/service/nuclei -target http://TARGET:8081 -rl 5 -c 3 -asREST Enumeration
curl http://TARGET:8081/service/rest/v1/repositories
curl http://TARGET:8081/service/rest/v1/search
curl http://TARGET:8081/service/rest/v1/search/assets
curl 'http://TARGET:8081/service/rest/v1/components?repository=REPO_NAME'Default / Initial Admin Password
Authenticated EL Injection RCE
Authenticated Groovy RCE
Windows Post-Exploitation
Last updated