mirror of
https://github.com/wooluo/POC00.git
synced 2026-03-17 23:04:51 +08:00
32 lines
965 B
Markdown
32 lines
965 B
Markdown
|
|
# 锐捷RG-ISG账号密码泄露漏洞
|
|||
|
|
|
|||
|
|
**一、漏洞简介**
|
|||
|
|
|
|||
|
|
<font style="color:rgb(51, 51, 51);">锐捷ISG存在账号密码泄露漏洞,可以获取密码的md5值, 解密后获取后台权限</font>
|
|||
|
|
|
|||
|
|
**二、影响版本**
|
|||
|
|
锐捷RG-ISG
|
|||
|
|
**三、资产测绘**
|
|||
|
|
|
|||
|
|
`title="RG-ISG"`
|
|||
|
|
●登录页面
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
**四、漏洞复现**
|
|||
|
|
|
|||
|
|
|
|||
|
|
首页查看源代码,搜索<font style="color:rgb(0, 0, 0);">persons </font>字段
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
> 更新: 2024-06-24 11:42:25
|
|||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/gq2226cz30ascc2d>
|