angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains an operational exploit for CVE-2024-42640, targeting the angular-base64-upload library (versions prior to v0.1.21). The exploit is implemented in a single Python script ('angular-exp-git.py'), which automates the process of scanning a list of target URLs for the presence of the vulnerable library, verifying the version, and then exploiting the vulnerability by uploading a base64-encoded PHP webshell to the 'demo/server.php' endpoint. If successful, the webshell is accessible via the 'demo/uploads/' directory, granting the attacker remote code execution on the server. The script supports multi-threaded scanning and exploitation, making it suitable for mass exploitation campaigns. The repository also includes a README with usage instructions and vulnerability details, and a standard license file. The main attack vector is network-based, exploiting exposed HTTP endpoints on web servers running the vulnerable library.
This repository provides a working exploit for CVE-2024-42640, a critical unauthenticated remote code execution vulnerability in the angular-base64-upload library (versions prior to v0.1.21). The exploit targets the demo/server.php endpoint, which allows arbitrary file uploads without authentication. The main exploit script (exploit.py) is written in Python and automates the process of checking for the vulnerable version, uploading a PHP web shell or reverse shell, and providing an interactive shell interface for command execution. The script supports both a simple web shell (allowing arbitrary command execution via HTTP requests) and a reverse shell (using a payload from pentestmonkey). The fix.sh script is a Bash utility to detect and remove the vulnerable demo directory, and to check for signs of prior exploitation by comparing file hashes and reporting unknown PHP files. The repository is well-documented, with a README explaining the vulnerability, usage instructions, and remediation steps. The exploit is operational and provides a real, working payload for remote code execution. Key fingerprintable endpoints include the vulnerable server.php upload endpoint and the uploads directory where payloads are stored and executed.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.