
Python-Proof-of-Concept-Exploit für CVE-2023-6553, der nicht authentifizierte Remote-Codeausführung über eine PHP-Filterkette im Backup-Migration-WordPress-Plugin demonstriert.
Nicht authentifizierte Remote-Codeausführung im Backup-Migration-Plugin (WordPress).
$ python exploit.py
Das folgende PHP-Skript wird ausgeführt.
<?php `date > out.txt`; ?>