CVE-2023-43364
CRITICALsearchor < 2.4.2 - Remote Code Execution via CLI Input
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2023-43364. PoCs published by jonathan-corbin, Herick-Costa, Kl3lCrypt.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-43364, an unauthenticated code execution vulnerability in Searchor <= 2.4.0. The exploit leverages an eval() injection in the query parameter to achieve remote command execution via a crafted payload.
Description
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
Exploits (5)
This repository contains a functional exploit for CVE-2023-43364, an unauthenticated code execution vulnerability in Searchor <= 2.4.0. The exploit leverages an eval() injection in the query parameter to achieve remote command execution via a crafted payload.
The repository contains a functional exploit for CVE-2023-43364, demonstrating RCE in Searchor < 2.4.2 via unsafe `eval()` usage. The PoC includes multiple payloads for command execution and reverse shells.
The repository contains a functional exploit for CVE-2023-43364, which targets a critical RCE vulnerability in Searchor CLI (≤2.4.1) due to unsafe use of `eval()`. The exploit crafts a malicious payload to achieve remote code execution via a reverse shell.
This repository contains a functional Python exploit for CVE-2023-43364, targeting an insecure eval() implementation in Searchor 2.4.0. The exploit crafts a malicious payload to achieve RCE via a reverse shell using busybox.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H