CVE-2023-6895: Hikvision IP ping.php – Command Execution

CVE-2023-6895: Hikvision IP ping.php - Command Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2023-6895: Hikvision IP ping.php – Command Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-6895: Hikvision IP ping.php – Command Execution

漏洞描述

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as critical. This vulnerability affects unknown code of the file /php/ping.php. The manipulation of the argument jsondata[ip] with the input netstat -ano leads to os command injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. VDB-248254 is the identifier assigned to this vulnerability.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享