跳转到帖子

Calibre Python Code Injection (CVE-2024-6782)

recommended_posts

发布于
  • Members

Calibre Python Code Injection (CVE-2024-6782)

Disclosed
07/31/2024
Created
08/08/2024

Description

This module exploits a Python code injection vulnerability in the Content Server component of Calibre v6.9.0 - v7.15.0. Once enabled (disabled by default), it will listen in its default configuration on all network interfaces on TCP port 8080 for incoming traffic, and does not require any authentication. The injected payload will get executed in the same context under which Calibre is being executed.

Author(s)

  • Amos Ng
  • Michael Heinzl

Platform

Linux,Unix,Windows

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 694
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…