mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-07-30 06:24:42 +00:00
27 lines
941 B
Markdown
27 lines
941 B
Markdown
![]() |
# JCG JHR-N835R 后台存在命令执行
|
|||
|
|
|||
|
# 一、漏洞简介
|
|||
|
JCG JHR-N835R 后台存在命令执行,通过 ; 分割 ping 命令导致任意命令执行
|
|||
|
|
|||
|
# 二、影响版本
|
|||
|
+ JCG JHR-N835R
|
|||
|
|
|||
|
# 三、资产测绘
|
|||
|
+ hunter`web.body="graphics/bottom.gif"`
|
|||
|
+ 特征
|
|||
|
|
|||
|

|
|||
|
|
|||
|
# 四、漏洞复现
|
|||
|
1. 通过默认账号`admin/admin`登录
|
|||
|
|
|||
|

|
|||
|
|
|||
|
2. 在后台系统工具那使用 PING工具,使用 ; 命令执行绕过
|
|||
|
|
|||
|

|
|||
|
|
|||
|
|
|||
|
|
|||
|
> 更新: 2024-02-29 23:57:13
|
|||
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/xq0kmca04hi8g2yd>
|