HackTheBox: Busqueda
Enumeration 1 export target=10.129.47.156 Port Scanning Add the domain to hosts: 1 sudo nano /etc/hosts Web Application (port 80) We see some kind of search engine: We see a version info on the footer: Searchor 2.4.0. Letβs search it if it is vulnerable. After googling, we find out that there is a CVE (CVE-2023-43364) with a public exploit PoC. https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection Download the PoC: 1 git clone https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection.git ...