Skip to content

Commit 03a2aea

Browse files
committed
automatic module_metadata_base.json update
1 parent bae70a4 commit 03a2aea

File tree

1 file changed

+62
-0
lines changed

1 file changed

+62
-0
lines changed

db/modules_metadata_base.json

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26193,6 +26193,68 @@
2619326193

2619426194
]
2619526195
},
26196+
"auxiliary_gather/solarwinds_servu_fileread_cve_2024_28995": {
26197+
"name": "SolarWinds Serv-U Unauthenticated Arbitrary File Read",
26198+
"fullname": "auxiliary/gather/solarwinds_servu_fileread_cve_2024_28995",
26199+
"aliases": [
26200+
26201+
],
26202+
"rank": 300,
26203+
"disclosure_date": null,
26204+
"type": "auxiliary",
26205+
"author": [
26206+
"sfewer-r7",
26207+
"Hussein Daher"
26208+
],
26209+
"description": "This module exploits an unauthenticated file read vulnerability, due to directory traversal, affecting\n SolarWinds Serv-U FTP Server 15.4, Serv-U Gateway 15.4, and Serv-U MFT Server 15.4. All versions prior to\n the vendor supplied hotfix \"15.4.2 Hotfix 2\" (version 15.4.2.157) are affected.",
26210+
"references": [
26211+
"CVE-2024-28995",
26212+
"URL-https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28995",
26213+
"URL-https://attackerkb.com/topics/2k7UrkHyl3/cve-2024-28995/rapid7-analysis"
26214+
],
26215+
"platform": "",
26216+
"arch": "",
26217+
"rport": 443,
26218+
"autofilter_ports": [
26219+
80,
26220+
8080,
26221+
443,
26222+
8000,
26223+
8888,
26224+
8880,
26225+
8008,
26226+
3000,
26227+
8443
26228+
],
26229+
"autofilter_services": [
26230+
"http",
26231+
"https"
26232+
],
26233+
"targets": null,
26234+
"mod_time": "2024-06-19 13:20:52 +0000",
26235+
"path": "/modules/auxiliary/gather/solarwinds_servu_fileread_cve_2024_28995.rb",
26236+
"is_install_path": true,
26237+
"ref_name": "gather/solarwinds_servu_fileread_cve_2024_28995",
26238+
"check": true,
26239+
"post_auth": false,
26240+
"default_credential": false,
26241+
"notes": {
26242+
"Stability": [
26243+
"crash-safe"
26244+
],
26245+
"SideEffects": [
26246+
26247+
],
26248+
"Reliability": [
26249+
26250+
]
26251+
},
26252+
"session_types": false,
26253+
"needs_cleanup": false,
26254+
"actions": [
26255+
26256+
]
26257+
},
2619626258
"auxiliary_gather/splunk_raw_server_info": {
2619726259
"name": "Splunk __raw Server Info Disclosure ",
2619826260
"fullname": "auxiliary/gather/splunk_raw_server_info",

0 commit comments

Comments
 (0)