
CVE-2021-22204 exiftool 원격 코드 실행
exiftool 임의 명령 실행
exploit.py 파일에서 리버스 쉘 받을 ip, port 설정 후 docker compose up 실행python3 exploit.py 파일을 실행할 경우 image.jpg 파일 공격 코드 생성image.jpg 파일을 다운로드하여 사용https://ine.com/blog/exiftool-command-injection-cve-2021-22204-exploitation-and-prevention-strategies https://github.com/convisolabs/CVE-2021-22204-exiftool