CVE-2024-28955
MEDIUMSharp and Toshiba Tec MFPs - Unprotected Sensitive Data Exposure via World-Readable Coredump Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-28955. PoCs published by Stuub.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-28995, targeting Serv-U's path traversal vulnerability to achieve local file read. The script includes version detection, predefined path testing for Windows/Linux, and supports custom paths/wordlists.
Description
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Exploits (1)
This repository contains a functional Python exploit for CVE-2024-28995, targeting Serv-U's path traversal vulnerability to achieve local file read. The script includes version detection, predefined path testing for Windows/Linux, and supports custom paths/wordlists.
References (7)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N