Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-1651 PoC — Torrentpier 代码问题漏洞

Source
Associated Vulnerability
Title:Torrentpier 代码问题漏洞 (CVE-2024-1651)
Description:Torrentpier TorrentPier是Torrentpier公司的一个公牛驱动的 BitTorrent 公共/私人跟踪器引擎。 Torrentpier 2.4.1版本存在代码问题漏洞,该漏洞源于存在反序列化漏洞,导致攻击者可以在服务器上执行任意命令。
Description
(Mirorring)
Readme
![GIF](https://media2.giphy.com/media/gkRApEeHSBlOU/giphy.gif?cid=ecf05e47fq2u1mlh9ws8h6ecidipdqek3mrqubguab6e9bh9&ep=v1_gifs_related&rid=giphy.gif)

Дырка в Torrentpier v2.4.1, приложение уязвимо к небезопасной десериализации, поэтому - позволяет выполнять произвольные команды на сервере.
File Snapshot

[4.0K] /data/pocs/8b19a12a11cd1cc6db16601297489ea34ceeab5a ├── [4.6K] 2024-1651_exploit.py └── [ 394] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.