当前位置:网站首页>Zero view h5s video platform getUserInfo information disclosure vulnerability cnvd-2020-67113
Zero view h5s video platform getUserInfo information disclosure vulnerability cnvd-2020-67113
2022-07-28 23:43:00 【Chu Bing】
Zero vision technology H5S Video platform GetUserInfo Information leaks CNVD-2020-67113
This article is only for study , It is strictly forbidden to use it for illegal purposes , Otherwise, we will be responsible for the consequences .
Vulnerability profile
Zero view technology ( Shanghai ) Ltd. is a leading video technology to serve customers , We are committed to simplifying the development of Internet of things video , Depending on HTML5 WebRTC And so on , Realize the simplification of video playback on the whole platform . Zero view technology ( Shanghai ) Co., LTD. H5S CONSOLE There is an unauthorized access vulnerability . An attacker can use the vulnerability to access the corresponding port in the background , Perform unauthorized operation .
Holes affect
Zero vision technology H5S Video platform
FOFA grammar
title="H5S Video platform |WEB"
Loophole recurrence
The login page

API Documents can be accessed without authorization
/doc/api.html

There is an interface with user account and password disclosure
/api/v1/GetUserInfo?user=admin&session=
边栏推荐
- Merkle tree
- How strong is this glue?
- 2022 R2 mobile pressure vessel filling test question simulation test platform operation
- MySQL log management, backup and recovery
- Arduino框架下STM32F103C系列单片机引脚映射关系
- MySQL functions
- 经典的拓扑排序问题——LeetCode207 课程表+LeetCode210 课程表II
- 刨根问底学 二叉树
- 新一代超安全蜂窝电池 思皓爱跑上市13.99万元起售
- 金仓数据库 KingbaseES与Oracle的兼容性说明(2. 数据类型)
猜你喜欢

Wechat applet development ③

2022 simulated examination platform operation of hoisting machinery command examination questions

MySQL transaction and storage system

Optimization and implementation of custom MVC

新一代超安全蜂窝电池 思皓爱跑上市13.99万元起售

Rhce第二天

互动滑轨屏在展厅中应用的制作步骤

可视化全链路日志追踪

Messages from students participating in the competition: memories of the 17th session

2022焊工(初级)上岗证题目及答案
随机推荐
Design idea of room inventory in hotel reservation system database
String string
Function function
电脑不知卸载什么,打不开计算器无法编辑截图功能打不开txt文件等等解决方案之一
Read the recent trends of okaleido tiger and tap the value and potential behind it
[self] - brush questions logic
How to add the index of a set in mongodb to another set in mongodb
1314_ Serial port technology_ Basic information of RS232 communication
Price for volume has encountered "six consecutive declines" in sales. Can Volvo, which is no longer safe, turn around?
Wechat applet development ③
2022 R2 mobile pressure vessel filling test question simulation test platform operation
General addition, deletion, modification and query of custom MVC
Meet the outbreak period with the integration of transportation and parking, rush for mass production or build a technical moat?
一文读懂Okaleido Tiger近期动态,挖掘背后价值与潜力
如何将一个mongodb中集合的索引 添加到另一个mongodb中集合中
Few people can really play in the "aftermarket" of the whole house intelligent fire collection
1314_串口技术_RS232通信基础的信息
以流量为主导的数字零售的发展模式,仅仅只是一个开始
MySQL log management, backup and recovery
Shenkaihong: on the river of Zhilian of all things, there is a bright moon of open source