关联漏洞
描述
Exploit CVE-2023-22518
介绍
# CVE-2023-22518 Exploit
## Description
This repository contains an exploit script for CVE-2023-22518. The script allows for unauthorized file uploads, potentially leading to remote code execution or other security vulnerabilities.
## Disclaimer
This repository is for educational and informational purposes only. Unauthorized use of this exploit script is strictly prohibited. Be responsible and respect ethical hacking principles.
## Vulnerability Details
- **CVE ID:** CVE-2023-22518
- **Vulnerability Type:** Unauthorized File Upload
- **Severity:** High
- **Affected Software:** [Specify affected software/application]
## Exploit Usage
1. Clone the repository to your local machine.
2. Run the script by providing the URL and the path to the .zip file you want to upload.
```bash
python3 exploit.py
Enter the URL: http://REDACTED:8090/json/setup-restore.action?synchronous=true
Enter the path to the .zip file: /path/xmlexport-20231109-060519-1.zip
文件快照
[4.0K] /data/pocs/543e4e2c5fb1cf07753d7b642d85db4fdfb8064f
├── [ 790] exploit.py
├── [ 959] README.md
└── [846K] xmlexport-20231109-060519-1.zip
0 directories, 3 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。