Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-40924. PoCs published by Çağatay Ceyhan.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated file upload vulnerability in Zoo Management System 1.0, allowing attackers to upload a malicious PHP file disguised as an animal image, leading to remote code execution (RCE). The exploit includes a crafted HTTP POST request with a multipart form containing a PHP web shell.
Description
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
Exploits (1)
This exploit demonstrates an unauthenticated file upload vulnerability in Zoo Management System 1.0, allowing attackers to upload a malicious PHP file disguised as an animal image, leading to remote code execution (RCE). The exploit includes a crafted HTTP POST request with a multipart form containing a PHP web shell.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H