
Python script to detect CVE-2024-41713 directory traversal in Apache HTTP Server, providing response snippets for verification. For educational and authorized testing only.
This repository contains a Python script to detect the presence of the CVE-2024-41713 vulnerability in Apache HTTP Server. CVE-2024-41713 is a directory traversal vulnerability that allows unauthorized attackers to access restricted resources on vulnerable servers.
The vulnerability arises due to improper sanitization of user-supplied paths. An attacker can exploit this by crafting malicious requests to traverse directories and access sensitive files or backend services.
Impact:
If exploited, this vulnerability can lead to unauthorized access, information disclosure, or potential privilege escalation.
requests library: Install it via pip:
pip install requests
Clone the repository:
git clone https://github.com/your-username/CVE-2024-41713.git
cd CVE-2024-41713
Run the script:
python3 cve-2024-41713-scanner.py
Enter the target URL when prompted. The script will test for the vulnerability using a specific payload.
Enter the target URL (e.g., http://example.com): http://vulnerable-site.com
Scanning http://vulnerable-site.com for CVE-2024-41713...
[!] Vulnerability Found:
Response Length: 1234
Response Snippet:
<ServiceList>
<Service>
<Name>ExampleService</Name>
<Endpoint>http://example.com</Endpoint>
</Service>
</ServiceList>
This tool is intended for educational purposes and authorized testing only.
Testing systems without proper authorization is unethical and illegal.
The author is not responsible for any misuse of this tool.
Feel free to submit issues or pull requests to improve the tool. All contributions are welcome!