Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-29272 PoC — VvvebJs 安全漏洞

Source
Associated Vulnerability
Title:VvvebJs 安全漏洞 (CVE-2024-29272)
Description:VvvebJs是Givan个人开发者的一个拖放网站生成器。 VvvebJs 1.7.7之前版本存在安全漏洞,该漏洞源于存在任意文件上传漏洞,允许未经身份验证的远程攻击者通过save.php中的sanitizeFileName参数执行任意代码并获取敏感信息。
Description
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.
File Snapshot

id: CVE-2024-29272 info: name: VvvebJs < 1.7.5 - Arbitrary File Upload author: s4e-io severit ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.