Analysis of CVE-2023-37474 in CopyParty
Автор: 0xdf
Загружено: 2025-01-23
Просмотров: 3870
Описание:
I recently came across CVE-2023-37474, a directory traversal vulnerability in CopyParty. In this video, I'll take the NVD description and a Snyk POC for the vulnerability and find the vulnerable code using grep.app. Then I'll understand how the code works, why it was a bug, and demo the vulnerable version on my host.
NVD CVE-2023037474: https://nvd.nist.gov/vuln/detail/CVE-...
Snyk POC: https://security.snyk.io/vuln/SNYK-PY...
☕ Buy Me A Coffee: https://www.buymeacoffee.com/0xdf
[00:00] Introduction
[00:49] NVD page
[01:14] Snyk POC
[01:37] Strategy
[02:00] Finding vulnerable code
[03:45] Python os.path.join demo
[05:20] Installing vulnerable version
[06:17] Running and exploiting vulnerable version
[08:28] Upgrading to recent version
[09:58] Conclusion
#copyparty #python #directory-traversal
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: