CVE-2024-31680
HIGHShibang Communications Co., Ltd. IP Network Intercom Broadcasting System - File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-31680. PoCs published by h3rkk.
AI-analyzed exploit summary The repository contains a functional proof-of-concept for CVE-2024-31680, demonstrating an arbitrary file upload vulnerability in Shibang Communications Co., Ltd.'s IP network intercom broadcasting system v1.0. The exploit targets the `/upload/my_parser.php` endpoint, which lacks file upload filtering, allowing an attacker to upload and execute arbitrary files.
Description
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
Exploits (1)
The repository contains a functional proof-of-concept for CVE-2024-31680, demonstrating an arbitrary file upload vulnerability in Shibang Communications Co., Ltd.'s IP network intercom broadcasting system v1.0. The exploit targets the `/upload/my_parser.php` endpoint, which lacks file upload filtering, allowing an attacker to upload and execute arbitrary files.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H