Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-34102 — CVE-2024-34102: Unauthenticated Magento XXE | Kitploit
工具/GitHubGitHub/th3gokul/cve-2024-34102
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubth3gokul/cve-2024-34102

CVE-2024-34102

CVE-2024-34102: Unauthenticated Magento XXE

查看仓库
1311年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-34102: 未经过身份验证的 Magento XXE

CVEHunter 工具用于 CVE-2024-34102 漏洞检测与利用,具备异步性能。


安装

root@kitploit:~
git clone https://github.com/th3gokul/CVE-2024-34102.git
cd CVE-2024-34102
pip install -r requirements.txt
python3 cvehunter.py --help

使用

root@kitploit:~
python3 cvehunter.py -h

  ____ __     __ _____  _   _                _               
 / ___|\ \   / /| ____|| | | | _   _  _ __  | |_   ___  _ __ 
| |     \ \ / / |  _|  | |_| || | | || '_ \ | __| / _ \| '__|
| |___   \ V /  | |___ |  _  || |_| || | | || |_ |  __/| |   
 \____|   \_/   |_____||_| |_| \__,_||_| |_| \__| \___||_| 
     CVE-2024-34102                  @th3gokul & Sanjaith3hacker

[Description]: Vulnerability Detection and Exploitation tool for CVE-2024-34102

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     [INF]: Specify a URL or domain for vulnerability detection
  -l LIST, --list LIST  [INF]: Specify a list of URLs for vulnerability detection
  -t THREADS, --threads THREADS
                        [INF]: Number of threads for list of URLs
  -proxy PROXY, --proxy PROXY
                        [INF]: Proxy URL to send request via your proxy
  -v, --verbose         [INF]: Increases verbosity of output in console
  -o OUTPUT, --output OUTPUT
                        [INF]: Filename to save output of vulnerable target]

关于:

CVEHunter 工具是 CVE-2024-34102 的利用工具,该工具的开发者是

  • Th3Gokul
  • Sanjaith3hacker @RevoltSecurities

我们特别感谢 bebik 和他的 SSRF 工具,该工具在我们的研究和利用过程中提供了帮助,以便了解回调、ping 并在利用此漏洞时找到准确结果。我们感谢他为开源社区做出的巨大贡献。

免责声明

该工具 ⚒️ 仅用于教育 📖 和道德目的,开发者不对任何非法利用行为负责。

下载工具