飛魚星 家用智能路由 cookie.cgi 權限繞過漏洞

From PwnWiki
Revision as of 21:18, 16 April 2021 by Pwnwiki (talk | contribs) (Created page with "==FOFA== <pre> title="飞鱼星家用智能路由" </pre> 訪問 index.html 時會請求 cookie.cgi <pre> http://xxx.xxx.xxx.xxx/index.html </pre> 頁面抓包 Drop掉 cook...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

FOFA

title="飞鱼星家用智能路由"


訪問 index.html 時會請求 cookie.cgi

http://xxx.xxx.xxx.xxx/index.html

頁面抓包 Drop掉 cookie.cgi,跳轉後台獲取了權限