
CVE-2024-34470 : HSC Mailinspector における認証不要のパストラバーサル脆弱性
CVE-2024-34470 の脆弱性検出および悪用ツールである CVEHunter で、非同期パフォーマンスを備えています。
git clone https://github.com/th3gokul/CVE-2024-34470.git
cd CVE-2024-34470
pip install -r requirements.txt
python3 cvehunter.py --help
python3 cvehunter.py -h
____ __ __ _____ _ _ _
/ ___|\ \ / /| ____|| | | | _ _ _ __ | |_ ___ _ __
| | \ \ / / | _| | |_| || | | || '_ \ | __| / _ \| '__|
| |___ \ V / | |___ | _ | |_| || | | || | | || |_ | __/| |
\____| \_/ |_____||_| |_| \__,_||_| |_| \__| \___||_|
CVE-2024-34470 @th3gokul
[Description]: Vulnerability Detection and Exploitation
tool for CVE-2024-34470
options:
-h, --help show this help message and exit
-u URL, --url URL [INF]: Specify a URL or domain
for vulnerability detection
-l LIST, --list LIST [INF]: Specify a list of URLs
for vulnerability detection
-t THREADS, --threads THREADS
[INF]: Number of threads for
list of URLs
-proxy PROXY, --proxy PROXY
[INF]: Proxy URL to send request
via your proxy
-v, --verbose [INF]: Increases verbosity of
output in console
-o OUTPUT, --output OUTPUT
[INF]: Filename to save output
of vulnerable target]
このツールは th3Gokul によって開発され、HSC Mailinspector の CVE-2024-34470 における未認証のパストラバーサル脆弱性を検出・悪用するためのものです。
このツールは教育および倫理的な目的のみで使用してください。開発者は不正な悪用について一切の責任を負いません。