CVE-2023-0678: PHPIPAM

CVE-2023-0678: PHPIPAM <v1.5.1 - Missing Authorization-渗透云记 - 专注于网络安全与技术分享
CVE-2023-0678: PHPIPAM
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-0678: PhpIPAM <v1.5.1 – Missing Authorization

漏洞描述

In phpIPAM 1.5.1, an unauthenticated user could download the list of high-usage IP subnets that contains sensitive information such as a subnet description, IP ranges, and usage rates via find_full_subnets.php endpoint. The bug lies in the fact that find_full_subnets.php does not verify if the user is authorized to access the data, and if the script was started from a command line.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享