Sploitus

Exploit for CVE-2024-28255

githubexploit · 2024-04-12

Exploit Code

README33 lines
## https://sploitus.com/exploit?id=1351A828-2BE1-53F7-87C5-D30F21011589
OpenMetadata_RCE (CVE-2024-28255)	Batch scan/exploit
  


1.このツールはセキュリティテストのみに使用されており、違法な攻撃については責任を負いません.

2.The tool is only used for security testing, and I am not responsible for any illegal attacks.

3.工具仅用于安全测试,任何非法攻击本人概不负责.



Help

Need to modify the DNS address in line 9 of the code.

```
python3 CVE-2024-28255.py --help

   _______      ________    ___   ___ ___  _  _        ___   ___ ___  _____ _____
  / ____\ \    / /  ____|  |__ \ / _ \__ \| || |      |__ \ / _ \__ \| ____| ____|
 | |     \ \  / /| |__ ______ ) | | | | ) | || |_ ______ ) | (_) | ) | |__ | |__
 | |      \ \/ / |  __|______/ /| | | |/ /|__   _|______/ / > _ 

All scan results will be saved in result.txt.

![image](https://github.com/YongYe-Security/CVE-2024-28255/blob/main/24_11-4-57-12-11-45.png)


The scanning results may not be accurate, for example: the target does not connect to the network, or the command does not exist.

![image](https://github.com/YongYe-Security/CVE-2024-28255/blob/main/24_12-4-2-12-01-704.png)