CVE-2024-46987 is a path traversal vulnerability in Camaleon CMS, a Ruby on Rails-based content management system. The flaw is reachable through the MediaController#download_private_file method and allows an authenticated user to traverse directories and download arbitrary files from the underlying web server, subject to the permissions of the application and operating system. The vulnerability results in unauthorized access to files outside the intended private media scope, leading to information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
Repository purpose: a Metasploit-style Python auxiliary scanner module that exploits CVE-2024-46987 (authenticated directory traversal) in Camaleon CMS to read arbitrary files from the server. Structure: - README.md: states this is a Metasploit module for CVE-2024-46987, based on Goultarde’s PoC. - camaleon_setup.md: lab/setup guide for installing Camaleon CMS 2.8.0 on Ubuntu (Rails/Ruby/Postgres) and running Metasploit against it (example port 3000). - camaleon_traversal.md: module-style documentation (options, verification steps, example output showing /etc/passwd disclosure). - camaleon_traversal.py: the actual exploit module. Exploit flow (camaleon_traversal.py): 1) Builds a base URL from rhost/rport/targeturi and optional vhost; supports HTTP or HTTPS via the ssl option. 2) GETs the admin login page to extract the Rails authenticity_token using regex: name="authenticity_token" value="...". 3) POSTs credentials (default admin/admin123) to the login endpoint and checks for 'logout' in the response body to confirm authentication. 4) Performs the traversal file read by calling the vulnerable endpoint /media/download_private_file with a crafted 'file' parameter consisting of '../' repeated depth times (default 13) plus the requested filepath (default /etc/passwd). On HTTP 200, prints the response body as the file contents. Capabilities/impact: - Authenticated arbitrary file read (information disclosure). No code execution or persistence is implemented; output is printed to console. Options allow changing target URI (/admin), traversal depth, vhost, and file path.
Repository contains a Python proof-of-concept exploit for CVE-2024-46987 (Camaleon CMS path traversal leading to arbitrary file read) and a README documenting the issue and usage. Structure: - CVE-2024-46987.py: Standalone Python3 exploit script using `requests.Session`. It supports (1) logging in with provided credentials, or (2) reusing an existing authenticated session via a raw cookie string. After authentication, it issues crafted GET requests to Camaleon’s admin media private download action, supplying a `file` query parameter prefixed with a configurable number of `../` sequences to escape the intended `private/` directory. - README.md: Explains the vulnerable sink (`fetch_file("private/#{params[:file]}")`), provides the vulnerable endpoint path, usage examples, and remediation guidance. Exploit capabilities: - Authenticated arbitrary file read (information disclosure) via directory traversal against `/admin/media/download_private_file`. - Configurable traversal depth (`-d/--depth`). - Convenience modes: `--interesting` iterates a curated list of high-value Linux/Rails paths (e.g., `/etc/passwd`, Rails `config/master.key`, `config/database.yml`), and `--interactive` provides an interactive file-read loop. - Operational details: disables urllib3 warnings; can disable TLS verification (`--no-verify`); includes a debug mode to help diagnose authentication issues. No evidence of RCE, persistence, or lateral movement is present; the primary impact is reading arbitrary files accessible to the web application process.
Repository contains a small, standalone authenticated LFI exploit for Camaleon CMS (CVE-2024-46987), targeting versions < 2.8.2. Structure is minimal: a README describing the vulnerability, requirements, and usage examples, plus a single Python script (exploit.py) that performs the exploit. Core behavior: exploit.py builds a URL to the Camaleon admin endpoint `/admin/media/download_private_file` and sends an HTTP GET request with a `file` query parameter containing a path traversal payload (`../../../../../../` + user-supplied file path). It authenticates by supplying an `auth_token` cookie value provided on the command line. If the response is HTTP 200 with content, it either prints the file contents (attempting UTF-8 then Latin-1 decoding) or writes raw bytes to a specified output file. Notable implementation details: SSL verification is disabled (verify=False) and urllib3 warnings are suppressed, indicating intended use against lab/CTF-style HTTPS targets. The exploit is operational for arbitrary file read but does not include post-exploitation features (no RCE, no shell), and relies entirely on having a valid authenticated token.
Repository contains a single Python proof-of-concept exploit (exploit.py) plus a short README. The exploit targets CVE-2024-46987 in Camaleon CMS (Ruby on Rails): a path traversal in MediaController's download_private_file method that allows an authenticated user to download arbitrary files. Structure/purpose: - README.md: Describes the vulnerability and intended CLI usage (url/username/password/file). - exploit.py: Implements the exploit flow using requests + BeautifulSoup. Exploit flow/capabilities: 1) Normalizes the provided base URL. 2) GETs the login page at /login and parses the HTML to extract the Rails CSRF authenticity_token from an <input name="authenticity_token"> field. 3) POSTs credentials to /login with the authenticity_token to obtain an authenticated session (cookies maintained by requests.Session). 4) Performs a GET request to /media/download_private_file with a crafted file parameter: "../../../../../.." + user-supplied --file, attempting to traverse directories and read the target file. 5) If HTTP 200, prints the response body (file contents); otherwise prints "File Not Found". No reverse shell or code execution is present; the impact is information disclosure via arbitrary file read, contingent on valid credentials and file permissions/server-side access controls.
Repository contains a single Python exploit script (cve-2024-46987.py) plus README and requirements.txt (requests). The script targets Camaleon CMS CVE-2024-46987, exploiting a path traversal/arbitrary file download via GET requests to /admin/media/download_private_file with a crafted 'file' parameter containing multiple '../' segments. Core capabilities: - Auth handling: can either (a) accept a user-supplied session cookie (_camaleon_cms_session) or (b) attempt to log in to /admin/login by first scraping an authenticity_token from the login page HTML and then POSTing username/password. - Manual mode (default): interactive prompt to request arbitrary file paths (e.g., /etc/passwd). It builds a traversal string, downloads the response, prints a 10-line preview when decodable, and saves the content under downloaded_files/. - SSH harvesting mode (--bruteforce-ssh): first attempts to read /etc/passwd via traversal to extract usernames with “valid shells” (bash/sh/zsh and also includes Windows strings like cmd.exe/powershell.exe). It then iterates through a fixed list of SSH-related filenames (id_rsa, id_ed25519, authorized_keys, etc.) and attempts to download them from /root/.ssh/ and /home/<user>/.ssh/, saving any hits to loot_ssh/. Notable implementation details/limitations: - The exploit is purely network-based (HTTP) and relies on the vulnerable endpoint being accessible; it assumes authentication may be required and provides cookie/credential options. - The README claims “Automated SSH Brute Force” but the code performs SSH key file harvesting via LFI/path traversal (no SSH protocol brute forcing). - In run_ssh_bruteforce(), a fallback to a default username dictionary references USERNAMES, which is not defined in the script; if /etc/passwd extraction fails, bruteforce mode will crash with NameError.
Repository contains a single Python PoC exploit script (CVE-2024-46987.py), plus README and MIT LICENSE. The exploit targets a post-authenticated path traversal in an admin file-download endpoint (hardcoded example: /admin/media/download_private_file) by supplying a file parameter with traversal sequences (../../../../../../etc/passwd). It uses requests.Session with a Prepared Request and then manually overrides prepared.url to ensure traversal sequences are sent verbatim (avoiding client-side URL/path normalization). The script requires the operator to set TARGET_URL and provide valid auth cookies (auth_token and session). On HTTP 200 it prints the response body (exfiltrated file contents); on redirects (301/302) it warns that the session is likely invalid/expired. No scanning, persistence, or RCE is implemented—this is a focused arbitrary file read PoC.
Repository contains a small Python PoC for CVE-2024-46987 (Camaleon CMS authenticated arbitrary file read/path traversal) plus a README. Structure: - CVE-2024-46987.py: Standalone exploit script. Creates a requests.Session with TLS verification disabled and suppresses urllib3 warnings. It first authenticates to the CMS by requesting /admin/login, scraping the CSRF authenticity_token from HTML, then POSTing credentials to the same endpoint. After login, it performs an LFI/path traversal request to a configurable endpoint (default: admin/media/download_private_file) by sending a GET with parameter file=<traversal><target_file>. If HTTP 200, it prints the raw response body (intended to be the file contents). - README.md: Describes the vulnerability location (MediaController#download_private_file), affected versions (2.8.0 to <2.8.2; notes it may work on 2.9.0), prerequisites, and usage examples. Main exploit capabilities: - Authenticated session establishment (CSRF token extraction + credential login). - Arbitrary file read from the server via path traversal in the 'file' parameter. Notable implementation details/limitations: - Requires valid credentials; no brute force. - No automatic detection of success beyond a loose check ('logout' in response or status_code==200). - Hardcoded traversal depth; relies on endpoint behavior to resolve to filesystem paths. - No post-processing of output; prints server response as-is.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.