Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add CVE-2024-5084 #10210

Merged
merged 3 commits into from
Jul 10, 2024
Merged

add CVE-2024-5084 #10210

merged 3 commits into from
Jul 10, 2024

Conversation

Kazgangap
Copy link
Contributor

CVE-2024-5084
poc link: https://github.com/WOOOOONG/CVE-2024-5084/blob/main/CVE-2024-5084_exploit.py

I used the PoC in the link. Instead of getting a reverse shell with PHP as in PoC, I upload a simple text file and check it. Then I check the uploaded file with matchers. I do not infect the system with a possible malicious shell.

Burp

get nonce
0

upload txt file
1

check txt file
2

Template Validation

I've validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Additional References:

@DhiyaneshGeek DhiyaneshGeek self-assigned this Jul 5, 2024
@DhiyaneshGeek DhiyaneshGeek added the Done Ready to merge label Jul 8, 2024
@DhiyaneshGeek DhiyaneshGeek merged commit cb6f9fa into projectdiscovery:main Jul 10, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done Ready to merge
2 participants