Sploitus

Exploit for CVE-2023-36281

kitploit ยท 2026-08-26

Exploit Code

MARKDOWN26 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-TAGOMARU-CVE-2023-36281
# CVE-2023-36281

CVE-2023-36281์— ๋Œ€ํ•œ PoC

๋‚˜๋Š” ์ด PoC๋ฅผ ์ฐธ์กฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์•ˆํƒ€๊น๊ฒŒ๋„ `subprocess.Popen`์˜ ์ธ๋ฑ์Šค๊ฐ€ Python ํ™˜๊ฒฝ๋งˆ๋‹ค ๋‹ค๋ฅด๊ธฐ ๋•Œ๋ฌธ์— ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์ œ PoC ์ฝ”๋“œ๋Š” ์ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

## ์„ค์น˜

`$ pip install -r requirements.txt`

## ์‹คํ–‰

### 1\. ๊ฐ ํ™˜๊ฒฝ๋งˆ๋‹ค ๋‹ค๋ฅผ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์ž์‹ ์˜ ํ™˜๊ฒฝ์—์„œ subprocss์˜ ์ธ๋ฑ์Šค๋ฅผ ๊ตฌํ•˜์„ธ์š”.

#### ์ž…๋ ฅ

`$ python get_index_of_subprocess.py`

#### ์ถœ๋ ฅ

root@kitploit:~
    
    
    subprcess.Popen index: 309.
    Replace target_index in attack_prompt.json with this value.