
4 changes to exploits/shellcodes/ghdb ImageMagick 7.1.0-49 - Arbitrary File Read ImageMagick 7.1.0-49 - Arbitrary File Read Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection pdfkit v0.8.7.2 - Command Injection
14 lines
No EOL
472 B
Text
14 lines
No EOL
472 B
Text
# Exploit Title: ImageMagick 7.1.0-49 - Arbitrary File Read
|
|
# Google Dork: N/A
|
|
# Date: 06/02/2023
|
|
# Exploit Author: Cristian 'void' Giustini
|
|
# Vendor Homepage: https://imagemagick.org/
|
|
# Software Link: https://imagemagick.org/
|
|
# Version: <= 7.1.0-49
|
|
# Tested on: 7.1.0-49 and 6.9.11-60
|
|
# CVE : CVE-2022-44268 (CVE Owner: Metabase Q Team
|
|
https://www.metabaseq.com/imagemagick-zero-days/)
|
|
# Exploit pre-requirements: Rust
|
|
|
|
|
|
# PoC : https://github.com/voidz0r/CVE-2022-44268 |