Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-41713 PoC — Mitel MiCollab 安全漏洞

Source
Associated Vulnerability
Title: Mitel MiCollab 安全漏洞 (CVE-2024-41713)
Description:A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
Description
A Python script to detect CVE-2024-41713, a directory traversal vulnerability in Apache HTTP Server, enabling unauthorized access to restricted resources. This tool is for educational purposes and authorized testing only. Unauthorized usage is unethical and illegal.
Readme
# CVE-2024-41713 Scanner

This repository contains a Python script to detect the presence of the CVE-2024-41713 vulnerability in Apache HTTP Server. CVE-2024-41713 is a directory traversal vulnerability that allows unauthorized attackers to access restricted resources on vulnerable servers.

## About CVE-2024-41713

The vulnerability arises due to improper sanitization of user-supplied paths. An attacker can exploit this by crafting malicious requests to traverse directories and access sensitive files or backend services.

**Impact:**  
If exploited, this vulnerability can lead to unauthorized access, information disclosure, or potential privilege escalation.

---

## Features

- Scans for directory traversal vulnerability related to CVE-2024-41713.
- Simple and easy-to-use Python script.
- Outputs detailed response snippets for vulnerability verification.

---

## Prerequisites

- **Python 3.x** installed on your system.
- **`requests` library**: Install it via pip:
  ```bash
  pip install requests
  ```

---

## Usage

1. Clone the repository:
   ```bash
   git clone https://github.com/your-username/CVE-2024-41713.git
   cd CVE-2024-41713
   ```

2. Run the script:
   ```bash
   python3 cve-2024-41713-scanner.py
   ```

3. Enter the target URL when prompted. The script will test for the vulnerability using a specific payload.

---

## Example Output

```
Enter the target URL (e.g., http://example.com): http://vulnerable-site.com
Scanning http://vulnerable-site.com for CVE-2024-41713...
[!] Vulnerability Found:
Response Length: 1234
Response Snippet:
<ServiceList>
  <Service>
    <Name>ExampleService</Name>
    <Endpoint>http://example.com</Endpoint>
  </Service>
</ServiceList>
```

---

## Disclaimer

This tool is intended for **educational purposes** and **authorized testing only**.  
Testing systems without proper authorization is unethical and illegal.  
The author is not responsible for any misuse of this tool.

---

## Contributing

Feel free to submit issues or pull requests to improve the tool. All contributions are welcome!
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →