CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal

CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal-渗透云记 - 专注于网络安全与技术分享
CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-51483: changedetection.io <= 0.47.4 – Path Traversal

漏洞描述

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source-file-///etc/passwd` can be used to retrieve local system files, where the more traditional `file-///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享