Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-40110 PoC — Poultry Farm Management System 安全漏洞

Source
Associated Vulnerability
Title:Poultry Farm Management System 安全漏洞 (CVE-2024-40110)
Description:Poultry Farm Management System是Poultry公司的一款功能齐全的家禽管理系统。 Poultry Farm Management System v1.0版本存在安全漏洞,该漏洞源于通过文件/farm/product.php的参数productimage包含未经身份验证的远程代码执行漏洞。
Description
Exploit para Poultry Farm Management System v1.0
Readme
# CVE-2024-40110 - Poultry Farm Management System v1.0

## Exploit para Poultry Farm Management System v1.0

Após encontrar um exploit no site Exploit-DB e o mesmo não funcionar, decidi realizar uma revisão no código e aprimorá-lo para adequar a necessidade. Uma vez que funcionou, decidi então, melhorar mais ainda, incluindo um pseudo web shell.

Todos os créditos são para Jerry Thomas (w3bn00b3r), que desenvolveu o script original.

Link do exploit original: https://www.exploit-db.com/exploits/52053

## Isenção de responsabilidade:

Código criado meramente para uso didático em ambiente controlado. Não executar contra alvos que não esteja devidamente autorizados.


## Poultry Farm Management System v1.0 Exploit

After finding an exploit on the Exploit-DB website and it not working, I decided to review the code and improve it to suit the needs. Since it worked, I decided to improve it even further, including a pseudo web shell.

Original exploit link: https://www.exploit-db.com/exploits/52053

All credit goes to Jerry Thomas (w3bn00b3r), who developed the original script.

## Disclaimer:

Code created merely for educational use in a controlled environment. Do not execute against targets that are not duly authorized.

![RCE](./img/1.jpeg)

![RCE](./img/2.jpeg)

![RCE](./img/3.jpeg)
File Snapshot

[4.0K] /data/pocs/92f2c4d7ff22f81e26a627ad1c660b148e17b5f0 ├── [3.0K] exploit.py ├── [4.0K] img │   ├── [147K] 1.jpeg │   ├── [ 68K] 2.jpeg │   ├── [176K] 3.jpeg │   └── [ 6] teste └── [1.3K] README.md 1 directory, 6 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.