
This is a python script to exploit Searchor 2.4.0 - the eval() function was implemented insecurely and can be exploited for RCE.
This machine relies on busybox being installed, as I wrote this for the Busqueda machine on HackTheBox. Just replace the payload with another reverse shell if you need to use something other than busybox.