CVE-2016-3714
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
- Imagemagick
- ≤ 6.9.3-9, 7.0.0-0, 7.0.1-0
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 8.4 HIGH
- EPSS
- 97.5% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2016-05-05
CVE-2016-3714 at NVD
12 known exploits for CVE-2016-3714
Proof-of-concept code and exploit modules indexed by Sploitus
pt-platform__container-breaking-in-goof
ethical-hacking-ctf
Exploit for Improper Input Validation in Imagemagick
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
ImageMagick 6.9.3-9 / 7.0.1-0 - Delegate Arbitrary Command Execution (ImageTragick)
Exploit for Improper Input Validation in Imagemagick
ImageMagick Delegate Arbitrary Command Execution
Wordpress 4.5.1 Remote Command Execute
ImageMagick 7.0.1-0 6.9.3-9 - ImageTragick Multiple Vulnerabilities
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
ImageMagick 命令执行漏洞 (ImageTragick)
ImageMagick 6.9.3-9 / 7.0.1-0 - Multiple Vulnerabilities (ImageTragick)