The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
https://github.com/Ismael-Ifetayo/Security-Reports
https://github.com/Nourah-ALobaeid/SSC-Ministry-Audit-DesertShadeV3
https://github.com/Harshit2519/Network-VAPT-Metasploitable2
https://github.com/sanasimran1403-jpg/pentest-report-generator
https://github.com/AyeshaKhan-Enigma/vulnerability-exploitation-initial-access
https://github.com/Mboatella25/metasploitable-pentest-lab
https://github.com/priyanshudubey454-hue/metasploitable2-vulnerability-assessment
https://github.com/animeshthube/nessus-vulnerability-assessment
https://github.com/Orevic21/wazuh-home-soc
https://github.com/pritishhhh/network-vulnerability-nmap
https://github.com/Geniusom18/metasploitable2-dvwa-pentest
https://github.com/EthicalHackingLabs/metasploitable2-exploitation-metasploit
https://github.com/NovocaineX/pentest-metasploit
https://github.com/Kartik0219/vuln-scanner
https://github.com/DesmondHinds94/S22_The_Verification_Protocol
https://github.com/Youneskc/SMB-Penetration-Testing-NTLM-Relay-Version-2-
https://github.com/JefferyCyber/Vulnerability-Scanner
https://github.com/uliyach45/penetration-testing-lab09
https://github.com/LMunizCiber/pentest-reports
https://github.com/baranii2105/nmap-recon-project
https://github.com/fai2an/nexacorp-vapt
https://github.com/okoroe845-create/network-security-audit-metasploitable2
https://github.com/Daviddoctor/Samba-CVE-2007-2447-Exploit-Username-Map-Script
https://github.com/Ritesh-GG/Vulnerability-Assessment-Lab
https://github.com/uliyach45/penetration-testing-labs
https://github.com/javiercabrera05/pentest-lab
https://github.com/r0tn3x/CVE-2007-2447
https://github.com/vig9610/Exploiting-Samba-on-Metasploitable-2
https://github.com/nulltrace1336/Samba-Exploit-CVE-2007-2447
https://github.com/nika0x38/CVE-2007-2447
https://github.com/RedTeamShanks/Local-Network-Vulnerability-Assessment
https://github.com/beyioku/vulnerability-assessment-lab
https://github.com/aparnaa19/CVE-Exploits-on-Metasploitable2
https://github.com/elphon/CVE-2007-2447-Exploit
https://github.com/noob-hacker572/CVE-Exploits
https://github.com/GoulongWang/CVE-Writeup
https://github.com/IamLucif3r/CVE-2007-2447-Exploit
https://github.com/J03-T/ExploitScripts
https://github.com/EchoSl0w/CVE
https://github.com/dugisan3rd/exploit
https://github.com/Aviksaikat/CVE-2007-2447
https://github.com/HerculesRD/PyUsernameMapScriptRCE
https://github.com/mr-l0n3lly/CVE-2007-2447
https://github.com/Nosferatuvjr/Samba-Usermap-exploit
https://github.com/xbufu/CVE-2007-2447
https://github.com/Alien0ne/CVE-2007-2447
https://github.com/Ziemni/CVE-2007-2447-in-Python
https://github.com/xlcc4096/exploit-CVE-2007-2447
https://github.com/nickvourd/smb-usermap-destroyer
https://github.com/JoseBarrios/CVE-2007-2447
https://github.com/b1fair/smb_usermap
https://github.com/Unix13/metasploitable2
https://github.com/amriunix/CVE-2007-2447
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10062
https://issues.rpath.com/browse/RPL-1366
http://www.xerox.com/downloads/usa/en/c/cert_XRX08_001.pdf
http://www.vupen.com/english/advisories/2008/0050
http://www.vupen.com/english/advisories/2007/3229
http://www.vupen.com/english/advisories/2007/2732
http://www.vupen.com/english/advisories/2007/2281
http://www.vupen.com/english/advisories/2007/2210
http://www.vupen.com/english/advisories/2007/2079
http://www.vupen.com/english/advisories/2007/1805
http://www.ubuntu.com/usn/usn-460-1
http://www.trustix.org/errata/2007/0017/
http://www.securitytracker.com/id?1018051
http://www.securityfocus.com/bid/25159
http://www.securityfocus.com/bid/23972
http://www.securityfocus.com/archive/1/468670/100/0/threaded
http://www.securityfocus.com/archive/1/468565/100/0/threaded
http://www.samba.org/samba/security/CVE-2007-2447.html
http://www.redhat.com/support/errata/RHSA-2007-0354.html
http://www.openwall.com/lists/oss-security/2025/10/16/2
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html
http://www.novell.com/linux/security/advisories/2007_14_sr.html
http://www.mandriva.com/security/advisories?name=MDKSA-2007:104
http://www.kb.cert.org/vuls/id/268336
http://www.debian.org/security/2007/dsa-1291
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906
http://securityreason.com/securityalert/2700
http://security.gentoo.org/glsa/glsa-200705-15.xml
http://secunia.com/advisories/28292
http://secunia.com/advisories/27706
http://secunia.com/advisories/26909
http://secunia.com/advisories/26235
http://secunia.com/advisories/26083
http://secunia.com/advisories/25772
http://secunia.com/advisories/25675
http://secunia.com/advisories/25567
http://secunia.com/advisories/25289
http://secunia.com/advisories/25270
http://secunia.com/advisories/25259
http://secunia.com/advisories/25257
http://secunia.com/advisories/25256
http://secunia.com/advisories/25255
http://secunia.com/advisories/25251
http://secunia.com/advisories/25246
http://secunia.com/advisories/25241
http://secunia.com/advisories/25232
http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=534
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01067768