Home

Description

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

PUBLISHED Reserved 2024-08-25 | Published 2026-05-08 | Updated 2026-05-08 | Assigner mitre

References

github.com/malwaredllc/byob

blog.chebuya.com/...icated-remote-command-execution-on-byob/

raw.githubusercontent.com/.../unix/webapp/byob_unauth_rce.rb

cve.org (CVE-2024-45257)

nvd.nist.gov (CVE-2024-45257)

Download JSON