Command Injection in sofianehamlaoui/lockdoor-framework
Valid
Reported on
Jun 27th 2021
✍️ Description
inurlbr function is vulnerable to CI of exploitation.py
🕵️♂️ Proof of Concept
// PoC
https://drive.google.com/file/d/1HpID3CrNAqK7t0C2JttP75Eqptha6r-D/view?usp=sharing
💥 Impact
command run as root. So an attacker could do potential damage to the machine.
Occurrences
We have contacted a member of the
sofianehamlaoui/lockdoor-framework
team and are waiting to hear back
2 years ago
to join this conversation