In Searchor versions prior to 2.4.2, the main.py script uses the eval function on input received from the command line interface (CLI). This allows an attacker to inject and execute arbitrary Python code by supplying malicious input to the CLI, leading to potential compromise of the system running the vulnerable software.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one Python exploit script, CVE-2023-43364.py, targeting CVE-2023-43364 in Searchor 2.4.0. It posts a crafted query value to http://searcher.htb/search with engine=Brave. The query injects a Python expression that imports os and calls os.popen, allowing execution of a shell command on the server. The script prompts for an operator IP address and port, Base64-encodes a Bash /dev/tcp reverse shell, and has the injected command decode and execute it. It uses requests.Session() with browser-like Origin, Referer, and User-Agent headers, then prints the HTTP response status, request body, request headers, and encoded payload. This is an operational exploit rather than a detection utility because it delivers a configurable reverse-shell payload.
This repository is a small standalone Python proof-of-concept exploit for CVE-2023-43364 affecting Searchor versions prior to 2.4.2. The repo contains only two files: a single exploit script (CVE-2023-43364.py) and a README with usage guidance and references. The exploit script uses argparse to support three modes: (1) a test mode that sends an injected payload to run 'id', (2) a custom command mode that executes any attacker-supplied shell command, and (3) a reverse shell mode that sequentially tries four callback techniques. All exploitation is delivered via HTTP POST requests to a user-supplied target URL, with form fields 'engine=Google' and a malicious 'query' value. The injected payloads abuse Python expression/code execution primitives such as __import__('os').system(...) and exec(...), consistent with the README's description of unsafe eval() usage in Searchor. The reverse shell logic is more than a minimal PoC: it attempts multiple fallback methods to improve reliability across target environments. Specifically, it tries a Python socket reverse shell to <LHOST>:4444, then a bash /dev/tcp shell, then a telnet+mkfifo shell, and finally a busybox nc -e shell. This makes the exploit operational rather than purely demonstrative, though payload customization is still manual and limited. No hardcoded victim URL is present; the operator must provide the target endpoint. The main fingerprintable artifacts are the POST parameters ('engine' and 'query'), the callback port 4444, and the shell paths/techniques used on the target. Overall, the repository's purpose is straightforward: exploit Searchor RCE to obtain command execution or an interactive shell on a vulnerable server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.