
CVE-2022-4047 poc
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
@@@@@@@ @@@ @@@ @@@@@@@@ @@@@@@ @@@@@@@@ @@@@@@ @@@@@@ @@@ @@@@@@@@ @@@ @@@@@@@@
@@@@@@@@ @@@ @@@ @@@@@@@@ @@@@@@@@ @@@@@@@@@@ @@@@@@@@ @@@@@@@@ @@@@ @@@@@@@@@@ @@@@ @@@@@@@@
!@@ @@! @@@ @@! @@@ @@! @@@@ @@@ @@@ @@!@! @@! @@@@ @@!@! @@!
!@! !@! @!@ !@! @!@ !@! @!@!@ @!@ @!@ !@!!@! !@! @!@!@ !@!!@! !@!
!@! @!@ !@! @!!!:! @!@!@!@!@ !!@ @!@ @! !@! !!@ !!@ @!@!@!@!@ @!! @!! @!@ @! !@! @!! @!! @!!
!!! !@! !!! !!!!!: !!!@!@!!! !!: !@!!! !!! !!: !!: !!!@!@!!! !!! !@! !@!!! !!! !!! !@! !!!
:!! :!: !!: !!: !:! !!:! !!! !:! !:! :!!:!:!!: !!:! !!! :!!:!:!!: !!:
:!: ::!!:! :!: :!: :!: !:! :!: :!: !:::!!::: :!: !:! !:::!!::: :!:
::: ::: :::: :: :::: :: ::::: ::::::: :: :: ::::: :: ::::: ::: ::::::: :: ::: ::
:: :: : : : :: :: :: : ::: : : : : :: : ::: :: : ::: ::: : : : : ::: : :
usage: exploit.py [-h] [-u URL] [-f FILE]
CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload (Mass PHP File Upload)
options:
-h, --help show this help message and exit
-u URL, --url URL url
-f FILE, --file FILE url list
requests
pip3 install requestspython3 exploit.py -u urlpython3 exploit.py -f file_path