Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2023-20052 — Original standalone Proof-of-Concept exploit and execution harness for CVE-2023-20052 (ClamAV DMG XML Entity Expansion). | Kitploit
Tools/GitHubGitHub/tralsesec/cve-2023-20052
Vulnerability AnalysisExploitationShellcodePenetration TestingLearning & EducationPayload Development
GitHubtralsesec/cve-2023-20052

CVE-2023-20052

Original standalone Proof-of-Concept exploit and execution harness for CVE-2023-20052 (ClamAV DMG XML Entity Expansion).

Repository anzeigen
13vor 13 TagenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

CVE-2023-20052 Exploit

Functional, self-developed Proof-of-Concept (PoC) exploit for CVE-2023-20052, a vulnerability in ClamAV (versions <= 1.0.0, <= 0.105.1, and <= 0.103.7) enabling arbitrary file read via XML Entity Expansion (XXE) during DMG file parsing.

This repository provides an original, standalone execution script to demonstrate the exploit chain, inspect the parsing behavior, and validate defensive detection rules against vulnerable scanning agents.

Demonstration

Exploit Execution

Usage

git clone https://github.com/tralsesec/CVE-2023-20052.git
cd CVE-2023-20052
chmod +x exploit.sh
./exploit.sh

Disclaimer

This software is provided strictly for educational purposes and authorized security testing. The authors are not responsible for any direct or indirect harm, damage, or legal consequences resulting from the use of this tool. Use at your own risk.

Tool herunterladen