Are Your Web Applications Vulnerable to ImageTragick? Scan Them with Netsparker

Both the desktop edition and the online edition of Netsparker web application security scanner have been updated and can automatically detect the Remote Code Execution via file upload vulnerability in ImageMagick, which has been dubbed as ImageTragick.

What is ImageTragick?

Another day and another popularized vulnerability, or better, a collection of vulnerabilities. MagicTragick is a collection of vulnerabilities in a popular software suite called ImageMagick, which is used to resize, flip, mirror and do other image manipulation work.

Remote Code Execution in MagicTragick

One of the vulnerabilities is a direct impact one and can lead to a Remote Code Execution. In other words, an attacker can upload an image tampered with malicious code and once the vulnerability is exploited the attacker can execute code remotely. For more detailed information on ImageTragick refer to the vulnerability’s website.

