Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
# CVE-2024-40422
Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
pip install requests
You can read more on the vulnerability here:
https://medium.com/aardvark-infinity/cve-2024-40422-path-traversal-vulnerability-in-stitionai-devika-81cbf45718f3
登录后查看神龙缓存的 POC 文件快照
登录查看