> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2024-9290 Exploit Tool | Super Backup & Clone Vulnerability
- URL: https://darkwebinformer.com/cve-2024-9290-exploit-tool-super-backup-clone-vulnerability/
- Published: 2024-12-24T19:27:54.000Z
- Updated: 2025-09-04T22:24:52.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities, Tools

---

GitHub: <https://github.com/Jenderal92/CVE-2024-9290>

---

[](https://github.com/Jenderal92/CVE-2024-9290#cve-2024-9290-exploit-tool--super-backup--clone-vulnerability)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2024/12/128946812-1.png)

The tool targets WordPress websites that use the **Super Backup & Clone** plugin and are vulnerable to arbitrary file upload. It attempts to upload a malicious shell into the `/wp-content/uploads/isnapshots/` directory. Once uploaded, the tool validates the existence of the shell and logs successful uploads into a `shells.txt` file.

---

## **Features**

[](https://github.com/Jenderal92/CVE-2024-9290#features)

- **Multi-threading**: Processes up to 10 URLs simultaneously for faster exploitation.
- **Custom Shell Upload**: Uses the malicious shell hosted on GitHub as a payload.
- **Logging**: Logs successful exploits into `shells.txt` for easy reference.

---

## **Usage**

[](https://github.com/Jenderal92/CVE-2024-9290#usage)

### **Prerequisites**

[](https://github.com/Jenderal92/CVE-2024-9290#prerequisites)

1. Python 2.7 is required to run this tool.
2. Ensure you have the `requests` library installed:pip install requests

### **Steps to Use**

[](https://github.com/Jenderal92/CVE-2024-9290#steps-to-use)

1. Clone this repository or download the script.
2. Create a text file containing a list of target URLs, one URL per line.
3. Run the script:python CVE-2024-9290.py
4. Enter the path to the file containing the URLs when prompted.
5. The tool will attempt to exploit each target and log any successes to `shells.txt`.

---

## **Key Points**

[](https://github.com/Jenderal92/CVE-2024-9290#key-points)

- **Educational Use Only**: This tool is designed for ethical hacking and penetration testing under authorized conditions.
- **Do Not Misuse**: Unauthorized use is illegal and may result in severe consequences.
- **Customizable**: Users can modify the script for specific payloads or requirements.

---

**Disclaimer:**

I have written the disclaimer on the cover of Jenderal92\. You can check it [HERE !!!](https://github.com/Jenderal92/)