ImageMagick 7.1.0-49 - Arbitrary File Read

Author: Cristian Giustini
type: local
platform: multiple
port: 
date_added: 2023-04-05  
date_updated: 2023-04-24  
verified: 0  
codes: CVE-2022-44268  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 51261.txt  
# Exploit Title: ImageMagick  7.1.0-49 - Arbitrary File Read
# Google Dork: N/A
# Date: 06/02/2023
# Exploit Author: Cristian 'void' Giustini
# Vendor Homepage: https://imagemagick.org/
# Software Link: https://imagemagick.org/
# Version: <= 7.1.0-49
# Tested on: 7.1.0-49 and 6.9.11-60
# CVE : CVE-2022-44268 (CVE Owner: Metabase Q Team
https://www.metabaseq.com/imagemagick-zero-days/)
# Exploit pre-requirements: Rust


# PoC : https://github.com/voidz0r/CVE-2022-44268