
POC for CVE-2024-40348. Will attempt to read /etc/passwd from target
POC for CVE-2024-40348 Bazaar v1.4.3 and prior. Will attempt to read /etc/passwd from target.

This is a bulk scanning and exploitation tool for CVE-2024-40348: Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. This vulnerability was discovered by 4rdr.
python CVE-2024-40348.py -u http://target:7809 -p /etc/passwd
python CVE-2024-40348 -f file.txt -p /etc/passwd
For any suggestions or thoughts, please get in touch with me.
I like to create my own tools for fun, work and educational purposes only. I do not support or encourage hacking or unauthorized access to any system or network. Please use my tools responsibly and only on systems where you have clear permission to test.