
إثبات المفهوم لـ CVE-2023-50094 (حقن أوامر في rengine)
يستغل هذا النص البرمجي بلغة Python ثغرة حقن الأوامر الموثقة في reNgine 2.2.0. يستهدف الاستغلال المعامل nmap_cmd في إعدادات محرك المسح، مما يسمح للمهاجمين بتنفيذ أوامر عشوائية.
requests.استنساخ المستودع:
git clone https://github.com/example/rengine-exploit.git
cd rengine-exploit
pip install requests
تشغيل النص البرمجي:
python poc.py --url http://rengine.target.com --username admin --password securepassword123 --engine-id 2