
CVE-2023-5180 LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
HeimShell is an exploit for CVE-2023-51803, leveraging an arbitrary file-upload vulnerability in LinuxServer.io Heimdall (≤ 2.5.6). It will auto-detect the target version and either warn of exploitability or remote fetch a php shell defined by SHELL_URL
/settings and parses the Version field to ensure arbitrary upload capability exists./items/create and scrapes the hidden _token input./items) to find the dashboard entry matching the random tag./items/<id>/edit), finds icon or #appimage img element, and prints shell URL.python heimShell.py <base_url>
detected version: 2.4.13
☠ shell uploaded at: <base_url>/storage/icons/abc123DEF456.php
https://nvd.nist.gov/vuln/detail/CVE-2023-51803
https://rz.my/2024/06/cve-2023-51803-arbitrary-file-upload-in-linuxserverio-heimdall.html
This tool is for authorized security testing only. Unauthorized use against systems you do not own or have explicit permission to test is illegal and unethical.