CVE-2023-39141
HIGH NUCLEIziahamza/webui-aria2 - Path Traversal via Node Server File Handling
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-39141. PoCs published by Pr0t0c01, MartiSabate. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional Nuclei template for CVE-2023-39141, which exploits a path traversal vulnerability in Aria2 WebUI. The template sends a crafted GET request to retrieve sensitive files like /etc/passwd, and includes matchers to verify successful exploitation.
Description
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
Exploits (2)
The repository contains a functional Nuclei template for CVE-2023-39141, which exploits a path traversal vulnerability in Aria2 WebUI. The template sends a crafted GET request to retrieve sensitive files like /etc/passwd, and includes matchers to verify successful exploitation.
This repository contains a functional bash script that exploits CVE-2023-39141, a Local File Inclusion (LFI) vulnerability, to enumerate files on a remote server. The script uses a wordlist to probe paths and retrieves files if they exist (HTTP 200 response).
Nuclei Templates (1)
title:"Aria2 WebUI" || http.title:"aria2 webui"
title="aria2 webui"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N