
CVE-2021-22204 exiftool rce
exiftool 任意コマンド実行
exploit.pyファイルでリバースシェルを受け取るIP、ポートを設定後、docker compose upを実行しますpython3 exploit.pyファイルを実行すると、image.jpgファイルの攻撃コードが生成されますimage.jpgファイルをダウンロードして使用しますhttps://ine.com/blog/exiftool-command-injection-cve-2021-22204-exploitation-and-prevention-strategies https://github.com/convisolabs/CVE-2021-22204-exiftool