Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-3129
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Facade Ignition for Laravel 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Facade Ignition for Laravel是比利时Facade公司的一款运行在Laravel Web框架中的可自定义的错误页面。 Ignition for Laravel 2.5.2之前版本存在授权问题漏洞,该漏洞源于程序未进行正确的身份验证,攻击者可利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-n/a n/a -
II. Public POCs for CVE-2021-3129
#POC DescriptionSource LinkShenlong Link
1Exploit for CVE-2021-3129https://github.com/ambionics/laravel-exploitsPOC Details
2Laravel debug rcehttps://github.com/SNCKER/CVE-2021-3129POC Details
3Nonehttps://github.com/SecPros-Team/laravel-CVE-2021-3129-EXPPOC Details
4Nonehttps://github.com/crisprss/Laravel_CVE-2021-3129_EXPPOC Details
5Exploit for CVE-2021-3129https://github.com/nth347/CVE-2021-3129_exploitPOC Details
6Nonehttps://github.com/FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129POC Details
7Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)https://github.com/zhzyker/CVE-2021-3129POC Details
8CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞https://github.com/simonlee-hello/CVE-2021-3129POC Details
9Nonehttps://github.com/idea-oss/laravel-CVE-2021-3129-EXPPOC Details
10PoC for CVE-2021-3129 (Laravel)https://github.com/knqyf263/CVE-2021-3129POC Details
11Add revert shell https://github.com/cuongtop4598/CVE-2021-3129-ScriptPOC Details
12Laravel RCE (CVE-2021-3129)https://github.com/joshuavanderpoll/CVE-2021-3129POC Details
13CVE-2021-3129 POChttps://github.com/shadowabi/Laravel-CVE-2021-3129POC Details
14Unauthenticated RCE in Laravel Debug Mode <8.4.2https://github.com/JacobEbben/CVE-2021-3129POC Details
15Laravel debug mode - Remote Code Execution (RCE)https://github.com/hupe1980/CVE-2021-3129POC Details
16CVE-2021-3129-Laravel Debug modehttps://github.com/0nion1/CVE-2021-3129POC Details
17CVE-2021-3129 Exploit Checker By ./MrMadhttps://github.com/MadExploits/Laravel-debug-CheckerPOC Details
18Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exphttps://github.com/ajisai-babu/CVE-2021-3129-expPOC Details
19Laravel RCE CVE-2021-3129https://github.com/keyuan15/CVE-2021-3129POC Details
20Nonehttps://github.com/qaisarafridi/cve-2021-3129POC Details
21Nonehttps://github.com/Zoo1sondv/CVE-2021-3129POC Details
22Laravel RCE (CVE-2021-3129)https://github.com/miko550/CVE-2021-3129POC Details
23CVE-2021-3129 | Laravel Debug Mode Vulnerabilityhttps://github.com/withmasday/CVE-2021-3129POC Details
24Nonehttps://github.com/banyaksepuh/Mass-CVE-2021-3129-ScannerPOC Details
25Nonehttps://github.com/Axianke/CVE-2021-3129POC Details
26A exploit script for CVE-2021-3129https://github.com/cc3305/CVE-2021-3129POC Details
27CVE-2021-3129 | Laravel Debug Mode Vulnerabilityhttps://github.com/wmasday/CVE-2021-3129POC Details
28Laravel Debug Mode and Payloadhttps://github.com/piperpwn/CVE-2021-3129-POC Details
29CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞https://github.com/Y0s9/CVE-2021-3129POC Details
30CVE-2021-3129 Laravel Ignition RCE Exploithttps://github.com/0x0d3ad/CVE-2021-3129POC Details
31Nonehttps://github.com/GodOfServer/CVE-2021-3129POC Details
32Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4https://github.com/Prabesh01/hoh4POC Details
33## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.https://github.com/lukwagoasuman/CVE-2021-3129---Laravel-RCEPOC Details
34Laravel Debug Mode and Payloadhttps://github.com/piperpwn/CVE-2021-3129-piperpwnPOC Details
35Laravel version 8.4.2 and before with Ignition before 2.5.2 allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3129.yamlPOC Details
36Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/Laravel%20%E5%B0%8F%E4%BA%8E%208.4.2%20Debug%E6%A8%A1%E5%BC%8F%20_ignition%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2021-3129.mdPOC Details
37Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/Laravel%20Ignition%202.5.1%20%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2021-3129.mdPOC Details
38Nonehttps://github.com/chaitin/xray-plugins/blob/main/poc/manual/laravel-cve-2021-3129.ymlPOC Details
39https://github.com/vulhub/vulhub/blob/master/laravel/CVE-2021-3129/README.mdPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-3129
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-3129

No comments yet


Leave a comment