CVE-2021-33564
CRITICAL EXPLOITED IN THE WILD NUCLEIDragonfly <1.4.0 - Command Injection
Title source: llmExploitation Summary
CVE-2021-33564 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including mlr0p, dorkerdevil. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2021-33564, an argument injection vulnerability in the Dragonfly Ruby Gem. The exploit allows arbitrary file read and write operations via crafted ImageMagick commands.
Description
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.
Exploits (2)
This repository contains a functional exploit PoC for CVE-2021-33564, an argument injection vulnerability in the Dragonfly Ruby Gem. The exploit allows arbitrary file read and write operations via crafted ImageMagick commands.
The repository contains a functional Python script that exploits CVE-2021-33564, an argument injection vulnerability in the Dragonfly Ruby Gem, allowing arbitrary file read and write operations via crafted ImageMagick commands.
Nuclei Templates (1)
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H