
مسح PoC النهائي لـ CVE-2024-4367
⚠️ أداة أمنية حرجة | يكتشف CVE-2024-4367 (CVSS 9.8) - ثغرة تنفيذ الأكواد عن بُعد في PDF.js
يعمل على أي موقع ويب - بدون أي إعداد مطلوب
CVE-2024-4367 هي ثغرة حرجة في PDF.js (الإصدارات < 4.2.67) تسمح بـتنفيذ JavaScript عشوائي عبر ملفات PDF خبيثة. يقوم هذا الماسح بالتعرف تلقائيًا على حالات PDF.js المعرّضة للخطر على أي موقع ويب.
يحتوي PDF.js على خلل حيث يتم تنفيذ JavaScript المضمّنة في ملفات PDF دون عزل مناسب (sandboxing)، مما يسمح للمهاجمين بـ:
F12 لفتح أدوات المطور (DevTools)Enterأنشئ إشارة مرجعية بهذا الرابط:
javascript:(function(){const s=document.createElement('script');s.src='https://cdn.jsdelivr.net/gh/yourusername/CVE-2024-4367-Scanner/scanner.js';document.body.appendChild(s);})();
git clone https://github.com/yourusername/CVE-2024-4367-Scanner
cd CVE-2024-4367-Scanner
# Open any website and run the script
<embed><object>?pdf=, ?file=, ?src=).pdf┌─────────────────────────────────────────────────────────────┐
│ SCAN PROCESS FLOW │
├─────────────────────────────────────────────────────────────┤
│ │
│ 1. 📚 LOAD SCRIPTS │
│ ├─ External scripts (all <script src="">) │
│ └─ Inline scripts (all <script> tags) │
│ │
│ 2. 🔍 EXTRACT PDF.JS VERSION │
│ ├─ Pattern matching in code │
│ ├─ Package.json detection │
│ └─ Node_modules path parsing │
│ │
│ 3. 🎯 IDENTIFY VULNERABILITY │
│ ├─ version < 4.2.67 ? → VULNERABLE │
│ └─ version = 2.16.105 ? → VULNERABLE │
│ │
│ 4. 🖼️ LOCATE VIEWERS │
│ ├─ DOM element scanning │
│ └─ Attribute detection │
│ │
│ 5. ⚡ GENERATE POC │
│ ├─ Create test PDF │
│ └─ Provide download link │
│ │
│ 6. 📊 DISPLAY RESULTS │
│ ├─ Visual overlay │
│ ├─ Console report │
│ └─ Global variable storage │
│ │
└─────────────────────────────────────────────────────────────┘
╔═══════════════════════════════════════════════════════════════════════════════════╗
║ CVE-2024-4367 - UNIVERSAL PDF.js SCANNER ║
║ Detects vulnerable PDF.js versions and potential exploitation ║
╚═══════════════════════════════════════════════════════════════════════════════════╝
📚 PHASE 1: Scanning JavaScript Bundles for PDF.js
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[+] Found 42 external scripts
[+] Found 12 inline scripts
[1/42] Analyzing: vendor.bundle.js
→ PDF.js indicator found: pdfjs-dist
✅ PDF.js version found: 2.16.105
🚨 VULNERABLE to CVE-2024-4367!
🎯 PHASE 4: Identifying Exploitation Vectors
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠️ URL parameter accepts PDF: file=/documents/report.pdf
⚠️ PDF upload form found
█████████████████████████████████████████████████████████████████████████████████
FINAL SCAN REPORT
█████████████████████████████████████████████████████████████████████████████████
🚨 CRITICAL VULNERABILITY CONFIRMED!
CVE: CVE-2024-4367
CVSS: 9.8 (CRITICAL)
Impact: Arbitrary JavaScript Execution
┌─────────────────────────────────────────────────────────────┐
│ CVE-2024-4367 SCAN RESULTS │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 📍 Target: example.com │
│ 📦 PDF.js: 2.16.105 │
│ 🎯 Vulnerable: YES │
│ 📄 Viewers: 3 │
│ ⚡ Vectors: 2 │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 🔴 CRITICAL - Upgrade Required │
└─────────────────────────────────────────────────────────────┘
# For Node.js projects
npm install pdfjs-dist@latest
# For CDN usage
# Update to version 4.2.67 or higher
// Set this before loading PDF.js
pdfjsLib.GlobalWorkerOptions.disableJavaScript = true;
Content-Security-Policy: script-src 'self';
object-src 'none';
worker-src 'none'