An open API service indexing awesome lists of open source software.

https://github.com/chocapikk/cve-2022-44877

Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
https://github.com/chocapikk/cve-2022-44877

Last synced: about 1 year ago
JSON representation

Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)

Awesome Lists containing this project

README

          

# CVE-2022-44877

## Overview

This bash script is used to test the vulnerability of web servers to CVE-2022-44877. The script performs a curl request to a target URL with a payload encoded in base64. If the target is vulnerable to the CVE-2022-44877 vulnerability, the elapsed time of the curl request will be greater than 3.5 seconds.

## Installation

```bash
sudo apt-get update
sudo apt-get install curl bc
git clone https://github.com/Chocapikk/CVE-2022-44877
cd CVE-2022-44877
chmod +x script.sh
```

## Usage

The script can be used in three different ways:

`scan`: To scan a single URL, run the following command:

```bash
./script.sh scan
```

`exploit`: To exploit a single URL, run the following command:

```bash
./script.sh exploit
```

`masscan`: To scan a list of URLs, either provide a file containing the list of URLs or pipe the list of URLs to the script:

```bash
./script.sh masscan

or

echo | ./script.sh masscan
```

# Requirements

The script requires `curl` to be installed on the system.

# Disclaimer

This script is for educational purposes only and should not be used for malicious purposes. The user is solely responsible for any actions taken with the script.