A PHP page that resizes uploaded images with ImageMagick 7.1.0-49, vulnerable to CVE-2022-44268: a PNG with a tEXt chunk whose keyword is profile and whose value is a path makes convert read that file and embed its content, hex-encoded, in the resized image the player downloads.
Pas commencéDockercommit ead4d0dx86_64 · aarch64Secret
Exploit CVE-2022-44268 with a crafted PNG to read files from the server and read the flag.
Le brief de ce lab se trouve dans son dépôt.