Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
[CVE-2026-66066] KindaRails2Shell:MATLAB 文件如何读取你的机密并在 Rails 上弹出 Shell
ethiack.com
| 研究 | CVE-2026-66066 |
#rce
|
#ruby-on-rails
|
#libvips
|
#file-read
|
#cve-2026-66066
摘要
Ethiack 技术剖析 CVE-2026-66066:一个声明为 image/png 的 MATLAB .mat 文件如何绕过 libvips 的格式识别,经 Rails ActiveStorage 实现任意文件读取,最终在默认配置上以 root 权限完成无需认证的远程代码执行。
收录时间
2026-07-31 12:38
原文 ↗
相关内容
KindaRails2Shell——通过 Active Storage 在 Rails 中实现严重 RCE(CVE-2026-66066)
(ethiack.com)
CVE-2026-66066 PoC:Rails Active Storage 文件读取到 RCE 的利用链
(github.com)
Grafana 6.4.3 任意文件读取
(swarm.ptsecurity.com)
Openfire 管理控制台中的漏洞
(swarm.ptsecurity.com)
ToolShell - A Critical SharePoint Vulnerability Chain under Active Exploitation
(blog.viettelcybersecurity.com)
Chamilo LMS:0day 如雨下,哈利路亚,0day 如雨下
(blog.quarkslab.com)
返回