![]() Signed-off-by: fanyunpeng <cn_2023@buaa.edu.cn> |
||
---|---|---|
.. | ||
CVE-2022-35411.py | ||
README.md |
README.md
rpc.py 0.6.0 - Remote Code Execution (RCE)
Google Dork: N/A
Date: 2022-07-12
Exploit Author: Elias Hohl
Vendor Homepage: https://github.com/abersheeran
Software Link: https://github.com/abersheeran/rpc.py
Version: v0.4.2 - v0.6.0
Tested on: Debian 11, Ubuntu 20.04
CVE : CVE-2022-35411
Usage
python CVE-2022-35411.py
reference
http://packetstormsecurity.com/files/167872/rpc.py-0.6.0-Remote-Code-Execution.html
491e7a841e
Patch Third Party Advisory
https://github.com/ehtec/rpcpy-exploit Third Party Advisory
https://medium.com/@elias.hohl/remote-code-execution-0-day-in-rpc-py-709c76690c30