Update Ruijie_EWEB_Network_Management_System_flwo.control.php_type_Arbitrary_Command_Execution_Vulnerability.md

This commit is contained in:
Goby 2023-09-07 22:33:55 +08:00 committed by GitHub
parent a7f75d359d
commit e1c0025ff9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -4,7 +4,7 @@
| :----: | :-----| | :----: | :-----|
| **Chinese name** | Ruijie-EWEB 网管系统 flwo.control.php 文件 type 参数任意命令执行漏洞 | | **Chinese name** | Ruijie-EWEB 网管系统 flwo.control.php 文件 type 参数任意命令执行漏洞 |
| **CVSS core** | 9.8 | | **CVSS core** | 9.8 |
| **FOFA Query** (click to view the results directly)| [(body="<span class=\"resource\" mark=\"login.copyRight\">锐捷网络</span>" && body="login.getDeviceInfo") \| title="锐捷网络-EWEB网管系统"]((https://en.fofa.info/result?qbase64=KGJvZHk9IjxzcGFuIGNsYXNzPVwicmVzb3VyY2VcIiBtYXJrPVwibG9naW4uY29weVJpZ2h0XCI%2B6ZSQ5o23572R57ucPC9zcGFuPiIgJiYgYm9keT0ibG9naW4uZ2V0RGV2aWNlSW5mbyIpIHx8IHRpdGxlPSLplJDmjbfnvZHnu5wtRVdFQue9keeuoeezu%2Be7nyI%3D)) | | **FOFA Query** (click to view the results directly)| [(body="<span class=\"resource\" mark=\"login.copyRight\">锐捷网络</span>" && body="login.getDeviceInfo") \|\| title="锐捷网络-EWEB网管系统"]((https://en.fofa.info/result?qbase64=KGJvZHk9IjxzcGFuIGNsYXNzPVwicmVzb3VyY2VcIiBtYXJrPVwibG9naW4uY29weVJpZ2h0XCI%2B6ZSQ5o23572R57ucPC9zcGFuPiIgJiYgYm9keT0ibG9naW4uZ2V0RGV2aWNlSW5mbyIpIHx8IHRpdGxlPSLplJDmjbfnvZHnu5wtRVdFQue9keeuoeezu%2Be7nyI%3D)) |
| **Number of assets affected** | 11544 | | **Number of assets affected** | 11544 |
| **Description** | Ruijie Network Management System is a new generation of cloud based network management software developed by Beijing Ruijie Data Era Technology Co., Ltd. With the slogan of "Innovative Network Management and Information Security in the Data Age", it is positioned as a unified solution for terminal security, IT operations, and enterprise service-oriented management.Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server. | | **Description** | Ruijie Network Management System is a new generation of cloud based network management software developed by Beijing Ruijie Data Era Technology Co., Ltd. With the slogan of "Innovative Network Management and Information Security in the Data Age", it is positioned as a unified solution for terminal security, IT operations, and enterprise service-oriented management.Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server. |
| **Impact** | Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server. | | **Impact** | Attackers can use this vulnerability to arbitrarily execute code on the server side, write backdoors, obtain server permissions, and then control the entire web server. |