Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-22515-File-Upload-Vulnerability | Kitploit
Tools/GitHubGitHub/orange-418/cve-2024-22515-file-upload-vulnerability
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHuborange-418/cve-2024-22515-file-upload-vulnerability

CVE-2024-22515-File-Upload-Vulnerability

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
12 years agoNot yet reviewed

CVE-2024-22515: File Upload Vulnerability in Agent DVR

Information

Description

In iSpyConnect.com Agent DVR 5.1.6.0, there is a lack of verification of file type for sound file uploads. This allows an authenticated user to upload any file type through the upload audio component simply by toggling to all files in the file open dialog.

Additional Information

This vulnerability may be chained with my previously submitted exploit, allowing both arbitrary file upload, and arbitrary file execution.

Affected Versions

  • Versions Affected: 5.1.6.0 (Note: Other versions may also be impacted)

Fixed Version

  • Version Fixed: 5.1.7.0

Researcher

  • Researcher: Dylan W. Como

Disclosure

  • Disclosure Link: GitHub Repository

References

  • NIST CVE Link: NVD - CVE-2024-22515

Proof-of-Concept Exploit

For those interested in understanding the technical details or replicating the security findings under controlled conditions, the proof-of-concept exploit is available at the following link:

  • GitHub PoC Repository
Download Tool