## https://sploitus.com/exploit?id=971E4B3E-82EE-5FFB-A3D2-B4C5CCE82706
PoC exploit for CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847. This exploit targets Juniper JunOS within SRX and EX Series products, achieving Remote Code Execution (RCE) by chaining four vulnerabilities. The exploit involves uploading an arbitrary PHP file to a restricted directory, uploading a PHP configuration file that loads the PHP file, and overwriting the environment variable PHPRC to execute the PHP function. The exploit can be specified using the --payload flag, with php_uname() set by default. The exploit is typically invoked using the python script watchtowr-vs-junos_juniper_2023-08-25.py with the target URL as an argument.