UNKNOWN PyPI
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
GHSA-2689-cw26-6cpj · CVE-2024-53305
Published · Modified
Description
An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-53305
- WEB https://github.com/benbusby/whoogle-search/commit/223f00c3c0533423114f99b30c561278bc0b42ba
- WEB https://fern89.github.io/posts/whoogle-rce
- WEB https://gist.github.com/fern89/ca5fe76ad81b4bc363e7341e523a1651
- PACKAGE https://github.com/benbusby/whoogle-search
Ready to move
Start Securing
Free, no credit card | First findings in minutes