
CVE-2024-4367 के लिए स्कैन एंड POC
⚠️ महत्वपूर्ण सुरक्षा उपकरण | CVE-2024-4367 (CVSS 9.8) का पता लगाता है - PDF.js रिमोट कोड निष्पादन भेद्यता
किसी भी वेबसाइट पर कार्य करता है - शून्य कॉन्फ़िगरेशन आवश्यक
CVE-2024-4367 PDF.js (संस्करण < 4.2.67) में एक गंभीर भेद्यता है जो दुर्भावनापूर्ण PDF फ़ाइलों के माध्यम से मनमाना JavaScript निष्पादन की अनुमति देती है। यह स्कैनर किसी भी वेबसाइट पर भेद्य PDF.js इंस्टेंस को स्वचालित रूप से पता लगाता है।
PDF.js में एक दोष है जहाँ PDF फ़ाइलों में एम्बेडेड JavaScript उचित सैंडबॉक्सिंग के बिना निष्पादित हो जाता है, जिससे हमलावर निम्न कार्य कर सकते हैं:
F12 दबाएँEnter दबाएँइस URL के साथ एक बुकमार्क बनाएँ:
javascript:(function(){const s=document.createElement('script');s.src='https://cdn.jsdelivr.net/gh/yourusername/CVE-2024-4367-Scanner/scanner.js';document.body.appendChild(s);})();
git clone https://github.com/yourusername/CVE-2024-4367-Scanner
cd CVE-2024-4367-Scanner
# Open any website and run the script
<embed> तत्व<object> डेटा टैग?pdf=, ?file=, ?src=).pdf स्वीकार करने वाले फ़ाइल इनपुट फ़ील्ड┌─────────────────────────────────────────────────────────────┐
│ SCAN PROCESS FLOW │
├─────────────────────────────────────────────────────────────┤
│ │
│ 1. 📚 LOAD SCRIPTS │
│ ├─ External scripts (all <script src="">) │
│ └─ Inline scripts (all <script> tags) │
│ │
│ 2. 🔍 EXTRACT PDF.JS VERSION │
│ ├─ Pattern matching in code │
│ ├─ Package.json detection │
│ └─ Node_modules path parsing │
│ │
│ 3. 🎯 IDENTIFY VULNERABILITY │
│ ├─ version < 4.2.67 ? → VULNERABLE │
│ └─ version = 2.16.105 ? → VULNERABLE │
│ │
│ 4. 🖼️ LOCATE VIEWERS │
│ ├─ DOM element scanning │
│ └─ Attribute detection │
│ │
│ 5. ⚡ GENERATE POC │
│ ├─ Create test PDF │
│ └─ Provide download link │
│ │
│ 6. 📊 DISPLAY RESULTS │
│ ├─ Visual overlay │
│ ├─ Console report │
│ └─ Global variable storage │
│ │
└─────────────────────────────────────────────────────────────┘
╔═══════════════════════════════════════════════════════════════════════════════════╗
║ CVE-2024-4367 - UNIVERSAL PDF.js SCANNER ║
║ Detects vulnerable PDF.js versions and potential exploitation ║
╚═══════════════════════════════════════════════════════════════════════════════════╝
📚 PHASE 1: Scanning JavaScript Bundles for PDF.js
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[+] Found 42 external scripts
[+] Found 12 inline scripts
[1/42] Analyzing: vendor.bundle.js
→ PDF.js indicator found: pdfjs-dist
✅ PDF.js version found: 2.16.105
🚨 VULNERABLE to CVE-2024-4367!
🎯 PHASE 4: Identifying Exploitation Vectors
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠️ URL parameter accepts PDF: file=/documents/report.pdf
⚠️ PDF upload form found
█████████████████████████████████████████████████████████████████████████████████
FINAL SCAN REPORT
█████████████████████████████████████████████████████████████████████████████████
🚨 CRITICAL VULNERABILITY CONFIRMED!
CVE: CVE-2024-4367
CVSS: 9.8 (CRITICAL)
Impact: Arbitrary JavaScript Execution
┌─────────────────────────────────────────────────────────────┐
│ CVE-2024-4367 SCAN RESULTS │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 📍 Target: example.com │
│ 📦 PDF.js: 2.16.105 │
│ 🎯 Vulnerable: YES │
│ 📄 Viewers: 3 │
│ ⚡ Vectors: 2 │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 🔴 CRITICAL - Upgrade Required │
└─────────────────────────────────────────────────────────────┘
# For Node.js projects
npm install pdfjs-dist@latest
# For CDN usage
# Update to version 4.2.67 or higher
// Set this before loading PDF.js
pdfjsLib.GlobalWorkerOptions.disableJavaScript = true;