Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-4040 PoC — CrushFTP 代码注入漏洞

Source
Associated Vulnerability
Title:CrushFTP 代码注入漏洞 (CVE-2024-4040)
Description:CrushFTP是一款文件传输服务器。 CrushFTP 10.7.1 和 11.1.0 之前版本存在安全漏洞,该漏洞源于允许低权限的远程攻击者从 VFS 沙箱之外的文件系统读取文件。
Readme
# CrushFTP-cve-2024-4040-poc
File Snapshot

[4.0K] /data/pocs/fbb232fff9c4778f34b6015e57bbb8643729f06f ├── [ 88M] CrushFTP.zip ├── [4.0K] CVE-2024-4040-EXPLOIT │   ├── [ 13K] crushed.py │   └── [ 125] README.md ├── [ 135] docker-compose.yaml ├── [ 331] Dockerfile ├── [ 587] k8s.yaml └── [ 28] README.md 1 directory, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.