
Este exploit intentará ejecutar comandos del sistema en objetivos SPIP.
Este exploit intentará ejecutar comandos del sistema en objetivos SPIP (CVE-2024-7954).

Esta es una herramienta de escaneo y explotación masiva para CVE-2024-7954: SPIP 4.2.8 permite a atacantes no autenticados lanzar RCE en objetivos SPIP. Esta herramienta está basada en esta Investigación de Seguridad.
pip install -r requirements.txt
POC for SPIP 4.2.8 vulnerability
options:
-h, --help show this help message and exit
-u U Target URL, example http://target:9090
-f F File containing list of URLs (one per line)
-c C Command to execute on the target, default is id
Para cualquier sugerencia o comentario, por favor ponte en contacto conmigo aquí.
Me gusta crear mis propias herramientas por diversión, trabajo y fines educativos únicamente. No apoyo ni fomento la piratería informática o el acceso no autorizado a ningún sistema o red. Usa mis herramientas de manera responsable y solo en sistemas donde tengas permiso explícito para realizar pruebas.