CVE-2021-36380: Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection

CVE-2021-36380: Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2021-36380: Sunhillo SureLine <8.7.0.1.1 - Unauthenticated OS Command Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-36380: Sunhillo SureLine <8.7.0.1.1 – Unauthenticated OS Command Injection

漏洞描述

Sunhillo SureLine <8.7.0.1.1 is vulnerable to OS command injection. The /cgi/networkDiag.cgi script directly incorporated user-controllable parameters within a shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. The following POST request injects a new command that instructs the server to establish a reverse TCP connection to another system, allowing the establishment of an interactive remote shell session.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享