关联漏洞
标题:
D-Link多款产品 安全漏洞
(CVE-2024-10914)
描述:D-Link DNS-320等都是中国友讯(D-Link)公司的一款NAS(网络附属存储)设备。 D-Link多款产品存在安全漏洞,该漏洞源于对参数name的错误操作会导致操作系统命令注入。以下产品及版本受到影响:D-Link DNS-320、DNS-320LW、DNS-325和DNS-340L 20241028版本及之前版本。
描述
CVE-2024-10914 Shell Exploit
介绍
# SilverX Exploit Tool
## 📌 Description
SilverX Exploit Tool is a penetration testing script designed to detect and exploit vulnerabilities in web applications. It provides a shell-like interface for executing commands remotely on vulnerable systems.
## ⚠️ Disclaimer
This tool is for educational and authorized security testing purposes only. Unauthorized use against any system without permission is illegal and unethical. Use responsibly.
## 🚀 Features
- **Automatic vulnerability detection**
- **Remote command execution**
- **Reverse shell support (Bash, Python, Netcat, PowerShell)**
- **File upload and download capabilities**
- **Shell-like command execution**
## 🔧 Installation
Ensure you have Python installed. Then, install the required dependencies:
```bash
pip install requests
```
## 🛠 Usage
Run the script using:
```bash
python CVE-2024-10914.py
```
### 📜 Commands:
- `pwd` - Print current directory
- `ls` - List directory contents
- `cd <directory>` - Change directory
- `cat <file>` - View file contents
- `download <file>` - Download file from target
- `upload <file>` - Upload file to target
- `reverse_shell` - Start a reverse shell
- `clear` - Clear terminal
- `exit` - Exit the exploit mode
## 🎯 Example Usage
```bash
python CVE-2024-10914.py
[?] Hədəf URL: http://target.com
[!] Hedef saytda zeiflik olub-olmadiğini yoxlayiriq...
[+] Zeiflik tapildi!
SilverShell (/) $ ls -la
```
## 🛡 Legal Disclaimer
The author takes no responsibility for any misuse or damage caused by this tool. Use only on systems you have explicit permission to test.
---
🔗 **Author:** SilverX
📢 **Telegram:** [t.me/silverxvip](https://t.me/silverxvip)
文件快照
[4.0K] /data/pocs/0e66ede6a536c6ccefd60221737fe476166a4cad
├── [5.7K] CVE-2024-10914.py
└── [1.7K] README.md
0 directories, 2 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。