CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
- Facade Ignition
- < 2.5.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.9% (100th percentile)
- NVD status
- Analyzed
- Published
- 2021-01-12
CVE-2021-3129 at NVD
37 known exploits for CVE-2021-3129
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Ignition Remote Code Execution Exploit
Ignition Remote Code Execution
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for Allocation of Resources Without Limits or Throttling in Th-Wildau Covid-19_Contact_Tracing
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Ignition 2.5.1 Remote Code Execution Exploit
Ignition 2.5.1 Remote Code Execution
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Exploit for CVE-2021-3129
Laravel 8.4.2 debug mode - Remote code execution
Exploit for CVE-2021-3129
Unauthenticated remote code execution in Ignition