CVE-2023-39141: Aria2 WebUI - Path traversal

HoneyLabs honeypots recorded 27 probes matching CVE-2023-39141 from 2 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /../../../../etc/passwd

Addresses probing it

Source IPProbesNetworkCountry
195.128.248.3315Virtual Systems LLCUkraine
109.224.17.21312Hulum Almustakbal Company for Communication Engineering and Services LtdIraq

Networks it comes from

ASNOrganisationProbesSource IPs
AS6698Virtual Systems LLC151
AS203214Hulum Almustakbal Company for Communication Engineering and Services Ltd121

Captured requests

  • /jnoj/web/polygon/problem/viewfile?id=1&name=../../../../../../../etc/passwd
  • /public/plugins/alertlist/../../../../../../../../../../../../../../../../../../../etc/passwd
  • /file/../../../../../../../../../../../../../../../../../../etc/passwd
  • /api/v1/openai-assistants-file/download?fileName=../../../../../etc/passwd

HTTP client fingerprints (JA4H)

  • ge11nn0400_628fde536a8d
  • ge11nn0400_8fd06a127c33
  • ge11nn0300_0db47b7d240d
  • ge11nn0400_cf1edba2959c

CVE report

CVE report

Open a specific CVE from the CVE tracker.