CVE-2022-29465
CRITICALAccusoft ImageGear 20.0 - Out-of-Bounds Write via PSD Header Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-29465. PoCs published by badguy233.
AI-analyzed exploit summary This Go-based PoC exploits CVE-2022-29465 (incorrectly referenced as CVE-2022-29464 in the README) to upload a malicious JSP file to a vulnerable WSO2 server via a path traversal vulnerability in the file upload endpoint. The exploit writes a webshell to a predictable location for remote command execution.
Description
An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Exploits (1)
This Go-based PoC exploits CVE-2022-29465 (incorrectly referenced as CVE-2022-29464 in the README) to upload a malicious JSP file to a vulnerable WSO2 server via a path traversal vulnerability in the file upload endpoint. The exploit writes a webshell to a predictable location for remote command execution.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H