A PHP upload page that resizes images with ImageMagick 6.9.2-10, vulnerable to ImageTragick (CVE-2016-3714): a crafted MVG or SVG file makes a delegate run a shell command built from an unescaped URL.
Pas commencéDockercommit a878d9dx86_64 · aarch64Secret
Exploit CVE-2016-3714 (ImageTragick) to run a command on the server.
Le brief de ce lab se trouve dans son dépôt.