Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-22514-Remote-Code-Execution | Kitploit
Tools/GitHubGitHub/orange-418/cve-2024-22514-remote-code-execution
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHuborange-418/cve-2024-22514-remote-code-execution

CVE-2024-22514-Remote-Code-Execution

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
2 years agoNot yet reviewed

CVE-2024-22514: Remote Code Execution in Agent DVR

Information

Description

iSpyConnect.com Agent DVR 5.1.6.0 contains a vulnerability which allows the file triggered by alert commands to be redirected. The modification can allow the commands function to trigger any file on the system under the permissions context of the program (root by default). This is done by editing the EXE param path in the objects.xml backup file, to create a modified objects.xml file, which can then be restored to through the dashboard. The restored dashboard will retain the new path placed in the objects.xml file which can then be triggered by alert commands.

Additional Information

This attack may be chained with an additional CVE I will submit which includes an arbitrary file upload vulnerability. By chaining these two together, any arbitrary file may be uploaded and executed remotely by an authenticated user.

Affected Versions

  • Versions Affected: 5.1.6.0 (Other versions may also be impacted)

Fixed Version

  • Version Fixed: 5.1.7.0

Researcher

  • Identified by: Dylan W. Como

Disclosure

  • Disclosure Link: GitHub Repository

References

  • NIST CVE Link: NVD - CVE-2024-22514

Proof-of-Concept Exploit

For detailed technical insights or to replicate the security findings in a controlled environment, refer to the proof-of-concept exploit available at:

  • GitHub PoC Repository
Download Tool