Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-34693 — An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled, potentially leading to local file disclosure on the server. Fixed in Superset versions 3.1.3 and 4.0.1. | Kitploit
Tools/GitHubGitHub/mr-r00t11/cve-2024-34693
Vulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationPenetration TestingDatabase Security
GitHubmr-r00t11/cve-2024-34693

CVE-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled, potentially leading to local file disclosure on the server. Fixed in Superset versions 3.1.3 and 4.0.1.

View Repository
222 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-34693 Exploit

This repository contains a sophisticated Python script to exploit the CVE-2024-34693 vulnerability in Apache Superset. The script sets up a rogue MySQL server and creates a malicious MariaDB connection to exfiltrate the content of a specified file from the target system.

[Screenshot_1.png]

Description

The CVE-2024-34693 vulnerability allows attackers with the ability to create arbitrary database connections to perform LOAD DATA LOCAL INFILE attacks, resulting in the reading of arbitrary files on the target system.

Features

  • Automated Setup: Sets up a rogue MySQL server using Bettercap.
  • Malicious Connection: Creates a malicious MariaDB connection to exfiltrate files.
  • Improved Logging: Provides detailed logging for better tracking and debugging.
  • Error Handling: Graceful error handling and meaningful error messages.

Prerequisites

  • Python 3.x
  • Bettercap
  • Docker and Docker Compose (for setting up the Apache Superset environment)

Installation

  1. Clone the repository:
git clone https://github.com/Mr-r00t11/CVE-2024-34693-exploit.git
cd CVE-2024-34693-exploit

Run the exploit script with appropriate arguments:

python3 exploit_cve_2024_34693.py http://localhost:8088 /etc/passwd

Replace http://localhost:8088 with the URL of your Apache Superset instance and /etc/passwd with the path of the file you wish to exfiltrate.

Download Tool