Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-24971 PoC — OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop

Source
Associated Vulnerability
Title:OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop (CVE-2025-24971)
Description:DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the **Apprise Notification** enabled. This issue has been addressed in commit `4ff8469d` and all users are advised to patch. There are no known workarounds for this vulnerability.
Description
CVE-2025-24971 exploit
File Snapshot

[4.0K] /data/pocs/e8572a3cbf2aac6a4fdd187fdfd84161ab3a7207 ├── [1.1K] CVE-2025-24971.py └── [ 34K] LICENSE 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →