Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-22514. PoCs published by Orange-418.
AI-analyzed exploit summary The repository describes a remote code execution vulnerability in Agent DVR 5.1.6.0, where the EXE param path in the objects.xml backup file can be modified to trigger arbitrary file execution. It mentions chaining with an arbitrary file upload vulnerability for full exploitation.
Description
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
Exploits (1)
The repository describes a remote code execution vulnerability in Agent DVR 5.1.6.0, where the EXE param path in the objects.xml backup file can be modified to trigger arbitrary file execution. It mentions chaining with an arbitrary file upload vulnerability for full exploitation.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H