ExifTool DjVu ANT Perl Injection
Posted by deepcore on May 13, 2021 – 2:22 am
This Metasploit module exploits a Perl injection vulnerability in the DjVu ANT parsing code of ExifTool versions 7.44 through 12.23 inclusive. The injection is used to execute a shell command using Perl backticks. The DjVu image can be embedded in a wrapper image using the HasselbladExif EXIF field.
Post a reply
You must be logged in to post a comment.