In m1k1o/blog, a lightweight self-hosted PHP blog, the image upload functionality fails to properly check errors from the imagecreatefrom* and image* functions. When these functions fail (e.g., due to a malformed or malicious image), PHP issues warnings and the upload function returns false, but the original uploaded file is still retained on disk. This could allow an attacker to upload files containing malicious payloads, bypassing intended security checks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, standalone authenticated RCE exploit for m1k1o's Blog, targeting CVE-2022-23626 despite the Python filename being inconsistently named cve-2022-23636.py. The repo contains only two files: one Python exploit script and one README with usage and vulnerability context. The exploit flow is straightforward: it first performs a GET to the supplied base URL to extract a PHPSESSID cookie and a CSRF token from the page content, then authenticates to /ajax.php using supplied credentials, then abuses the vulnerable /ajax.php?action=upload_image endpoint to upload a PHP webshell named shell.gif.php with a GIF89a magic header to bypass naive file validation. After upload, it requests the returned path directly to execute the payload. The payload supports two modes: arbitrary command execution supplied with --command, or a reverse shell using php -r with fsockopen to an attacker listener. This is a real exploit, not a detector, and it provides practical post-auth remote code execution against vulnerable deployments where uploaded PHP files are web-accessible and executable. The code is simple and operational, but not highly robust: error handling is minimal, token extraction is brittle string-splitting, and the trigger function appears syntactically incomplete in the provided content, though the intended behavior is clear from context and README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.