A file upload vulnerability exists in Shibang Communications Co., Ltd. IP network intercom broadcasting system version 1.0, specifically in the my_parser.php component. This flaw allows a local attacker to upload arbitrary files, which can lead to the execution of attacker-controlled code on the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2024-31680 affecting the Shibang Communications IP network intercom broadcasting system v1.0. It contains no executable exploit script; instead, it provides a Markdown write-up with a raw HTTP multipart request demonstrating an arbitrary file upload flaw. The described issue is that /upload/my_parser.php accepts uploaded files without filtering and stores them under /upload/files, enabling an attacker to upload a PHP file such as 123.php and then access it directly via the web server. Repository structure is very small: README.md only names the CVE, while POC.md contains the vulnerability description, screenshots, the vulnerable endpoint, an example target IP/port, and the manual exploitation steps. Because the repository only documents the HTTP request and verification path, it is best classified as a web-based POC for arbitrary file upload with potential follow-on remote code execution if the uploaded file type is executable by the server.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.