Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-27766 — Modified PoC for MariaDB v11.1 RCE via UDF, returning command output inline through SQL queries. Includes detailed code comparison and compilation instructions for Windows. | Kitploit
Tools/GitHubGitHub/y0un9eee/cve-2024-27766
Vulnerability AnalysisCode AnalysisExploitationLearning & EducationPayload DevelopmentDatabase SecurityBinary Exploitation
GitHuby0un9eee/cve-2024-27766

CVE-2024-27766

Modified PoC for MariaDB v11.1 RCE via UDF, returning command output inline through SQL queries. Includes detailed code comparison and compilation instructions for Windows.

View Repository
125 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-27766

MariaDB v11.1 RCE via UDF — modified PoC based on Ant1sec-ops/CVE-2024-27766.


Overview

AffectedMariaDB v11.1
Fixed in10.5.25 / 10.6.18 / 10.11.8 / 11.0.6 / 11.1.5 / 11.2.4 / 11.4.2+
TypeRCE via User-Defined Function (UDF)

MariaDB v11.1 allows an attacker with sufficient database privileges (FILE privilege + plugin directory write access) to register a malicious UDF and execute arbitrary OS commands through it.

Note: The MariaDB Foundation disputes this CVE on the grounds that no privilege boundary is crossed. Exploitation requires admin-level DB access or equivalent.


What's different from the original

The original PoC uses a longlong return type, so do_system() only returns whether the command succeeded — you can't see the output directly from SQL.

This version changes the return type to char *, which pipes stdout back as the query result. No out-of-band channel needed; just run SELECT do_system('whoami') and the output comes back inline.

Changes at a glance

OriginalThis PoC
Return typelonglongchar *
Executionsystem()_popen() + fgets() loop
SQL resultexit codecommand stdout
Memorynoneheap-allocated, freed in deinit

One thing worth noting: returning char * from a UDF requires MariaDB to know the buffer size upfront. do_system_init sets initid->max_length = 65536, matching the output buffer allocated in the main function.

Because the return type changed, RETURNS STRING must be used when registering the function — not RETURNS INTEGER as in the original.

CREATE FUNCTION do_system RETURNS STRING SONAME 'do_system.dll';

Requirements

  • Windows (uses _popen / _pclose)
  • MariaDB v11.1 (unpatched)
  • DB user with FILE privilege and plugin directory write access
  • MinGW-w64 or MSVC to compile

Disclaimer

For educational and research purposes only. Do not use against systems you don't own or have explicit permission to test.

Download Tool