mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 01:40:20 +00:00
add: Zabbix CVE-2022-23131
add: Tenda uploadWewifiPic RCE
This commit is contained in:
parent
2b0d45b839
commit
8b0f1aae4e
9
Tenda/uploadWewifiPic RCE/README.md
Normal file
9
Tenda/uploadWewifiPic RCE/README.md
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
# Tenda Auth uploadWewifiPic RCE
|
||||||
|
|
||||||
|
Tenda router is an efficient and practical router. There is a command execution vulnerability in the uploadWewifiPic route in the background of Tenda routers. Attackers can use the vulnerability to execute arbitrary commands to obtain server permissions.
|
||||||
|
|
||||||
|
FOFA **query rule**: [body="Tenda|登录" && body="tenda.css"](https://fofa.info/result?qbase64=Ym9keT0iVGVuZGF855m75b2VIiAmJiBib2R5PSJ0ZW5kYS5jc3Mi)
|
||||||
|
|
||||||
|
# Demo
|
||||||
|
|
||||||
|

|
BIN
Tenda/uploadWewifiPic RCE/Tenda_Auth_uploadWewifiPic_RCE.gif
Normal file
BIN
Tenda/uploadWewifiPic RCE/Tenda_Auth_uploadWewifiPic_RCE.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 1.2 MiB |
9
Zabbix/CVE-2022-23131/README.md
Normal file
9
Zabbix/CVE-2022-23131/README.md
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
# Zabbix Login Bypass (CVE-2022-23131)
|
||||||
|
|
||||||
|
Zabbix is an open source monitoring system. The system supports network monitoring, server monitoring, cloud monitoring and application monitoring, etc. A login bypass vulnerability exists in Zabbix that arises when SAML SSO authentication is enabled (not default). An unauthenticated malicious attacker could exploit the vulnerability to escalate privileges and gain administrator access to the Zabbix frontend.
|
||||||
|
|
||||||
|
FOFA **query rule**: [body="SAML" && (banner="zbx_session=" || header="zbx_session=")](https://fofa.info/result?qbase64=Ym9keT0iU0FNTCIgJiYgKGJhbm5lcj0iemJ4X3Nlc3Npb249IiB8fCBoZWFkZXI9InpieF9zZXNzaW9uPSIp)
|
||||||
|
|
||||||
|
# Demo
|
||||||
|
|
||||||
|

|
BIN
Zabbix/CVE-2022-23131/Zabbix_Login_Bypass_CVE_2022_23131.gif
Normal file
BIN
Zabbix/CVE-2022-23131/Zabbix_Login_Bypass_CVE_2022_23131.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 1.3 MiB |
Loading…
x
Reference in New Issue
Block a user