CVE-2021-44848: Thinfinity VirtualUI User Enumeration

CVE-2021-44848: Thinfinity VirtualUI User Enumeration-渗透云记 - 专注于网络安全与技术分享
CVE-2021-44848: Thinfinity VirtualUI User Enumeration
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-44848: Thinfinity VirtualUI User Enumeration

漏洞描述

Thinfinity VirtualUI (before v3.0), /changePassword returns different responses for requests depending on whether the username exists. It may enumerate OS users (Administrator, Guest, etc.)

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享