louie.rocks

Home

❯

Boxes

❯

PG CVE 2023 40582

PG-CVE-2023-40582

Apr 01, 20241 min read

  • npm
  • cve-2023-40582

Find open ports (22, 3000)

Forgot to take a screenshot.

Find that the web app uses the npm package find-exec v1.0.2

Pasted image 20240729045335

Find and execute an exploit for find-exec v1.0.2

A google search led to this source which led to this Issue on the tools’ GitHub repo. It seems it is vulnerable to command injection.

Pasted image 20240729050518

Pasted image 20240729050538

Obtain proof.txt

Pasted image 20240729050626


Created with Quartz v4.5.0 © 2025

  • GitHub
  • Discord Community