add CVE-2021-3019

This commit is contained in:
tardc 2021-01-13 10:41:35 +08:00
parent 1d670966e9
commit fef987fd0d
2 changed files with 11 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 418 KiB

View File

@ -0,0 +1,11 @@
# CVE-2021-3019 lanproxy Directory Traversal
ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.
**Affected version**: lanproxy 0.1
**[FOFA](https://fofa.so/result?q=header%3D%22Server%3A+LPS-0.1%22&qbase64=aGVhZGVyPSJTZXJ2ZXI6IExQUy0wLjEi&file=&file=) query rule**: header="Server: LPS-0.1"
# Demo
![](CVE-2021-3019.gif)