2022-05-25 15:32:50 +08:00
|
|
|
|
# 绿盟 BAS日志数据安全性分析系统 accountmanage 未授权访问漏洞
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞描述
|
|
|
|
|
|
|
|
|
|
|
|
绿盟 BAS日志数据安全性分析系统存在未授权访问漏洞,通过漏洞可以添加任意账户登录平台获取敏感信息
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞影响
|
|
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
|
绿盟 BAS日志数据安全性分析系统
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## FOFA
|
|
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
|
body="WebApi/encrypt/js-sha1/build/sha1.min.js"
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
## 漏洞复现
|
|
|
|
|
|
|
|
|
|
|
|
登录页面
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-05-25 15:32:50 +08:00
|
|
|
|
|
|
|
|
|
|
未授权页面
|
|
|
|
|
|
|
|
|
|
|
|
```
|
|
|
|
|
|
/accountmanage/index
|
|
|
|
|
|
```
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-05-25 15:32:50 +08:00
|
|
|
|
|
|
|
|
|
|
添加用户并登录
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|
2022-05-25 15:32:50 +08:00
|
|
|
|
|
|
|
|
|
|
使用账户登录后台
|
|
|
|
|
|
|
2022-12-05 11:09:28 +08:00
|
|
|
|

|