File tree Expand file tree Collapse file tree 1 file changed +61
-0
lines changed Expand file tree Collapse file tree 1 file changed +61
-0
lines changed Original file line number Diff line number Diff line change 23797
23797
}
23798
23798
]
23799
23799
},
23800
+ "auxiliary_gather/magento_xxe_cve_2024_34102": {
23801
+ "name": "Magento XXE Unserialize Arbitrary File Read",
23802
+ "fullname": "auxiliary/gather/magento_xxe_cve_2024_34102",
23803
+ "aliases": [
23804
+
23805
+ ],
23806
+ "rank": 300,
23807
+ "disclosure_date": "2024-06-11",
23808
+ "type": "auxiliary",
23809
+ "author": [
23810
+ "Sergey Temnikov",
23811
+ "Heyder"
23812
+ ],
23813
+ "description": "This module exploits a XXE vulnerability in Magento 2.4.7-p1 and below which allows an attacker to read any file on the system.",
23814
+ "references": [
23815
+ "CVE-2024-34102",
23816
+ "URL-https://github.com/spacewasp/public_docs/blob/main/CVE-2024-34102.md"
23817
+ ],
23818
+ "platform": "",
23819
+ "arch": "",
23820
+ "rport": 80,
23821
+ "autofilter_ports": [
23822
+ 80,
23823
+ 8080,
23824
+ 443,
23825
+ 8000,
23826
+ 8888,
23827
+ 8880,
23828
+ 8008,
23829
+ 3000,
23830
+ 8443
23831
+ ],
23832
+ "autofilter_services": [
23833
+ "http",
23834
+ "https"
23835
+ ],
23836
+ "targets": null,
23837
+ "mod_time": "2024-07-18 11:56:22 +0000",
23838
+ "path": "/modules/auxiliary/gather/magento_xxe_cve_2024_34102.rb",
23839
+ "is_install_path": true,
23840
+ "ref_name": "gather/magento_xxe_cve_2024_34102",
23841
+ "check": true,
23842
+ "post_auth": false,
23843
+ "default_credential": false,
23844
+ "notes": {
23845
+ "Stability": [
23846
+ "crash-safe"
23847
+ ],
23848
+ "Reliability": [
23849
+
23850
+ ],
23851
+ "SideEffects": [
23852
+ "ioc-in-logs"
23853
+ ]
23854
+ },
23855
+ "session_types": false,
23856
+ "needs_cleanup": false,
23857
+ "actions": [
23858
+
23859
+ ]
23860
+ },
23800
23861
"auxiliary_gather/manageengine_adaudit_plus_xnode_enum": {
23801
23862
"name": "ManageEngine ADAudit Plus Xnode Enumeration",
23802
23863
"fullname": "auxiliary/gather/manageengine_adaudit_plus_xnode_enum",
You can’t perform that action at this time.
0 commit comments