Skip to content

antisecc/CVE-2022-23935

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 

Repository files navigation

CVE-2022-23935

The Exiftool software program, in versions prior to 12.38, has a security vulnerability that can be exploited through a specially crafted filename.

This vulnerability allows for command injection, where an attacker can execute arbitrary commands on the system by appending a pipe character '|' to the end of the filename, causing the file to be treated as a command to be executed rather than as a regular file.

As a result, any file on the system that has this naming convention can be potentially used to execute malicious code.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages