漏洞描述 海康威视综合安防系统的 /center/api/installation/detection 接口存在远程代码执行漏洞。攻击者可以通过构造特定的POST请求,在machines.id字段中注入恶意代码,从而在服务器上执行任意命令。该漏洞的存在使得未经授权的远程攻击者可以完全控制受影响的系统。
相关漏洞推荐 honeypot-detection: Honeypot Detection POC CVE-2024-34061: Changedetection.io <=v0.45.21 - Cross-Site Scripting POC CVE-2024-51483: Changedetection.io <= 0.47.4 - Path Traversal POC azure-takeover-detection: Microsoft Azure Takeover Detection POC htpasswd-detection: Apache htpasswd Config - Detect POC changedetection-unauth: Changedetection.io Dashboard - Exposure POC linkerd-ssrf-detection: Linkerd SSRF detection POC cargo-takeover: cargo takeover detection POC frontify-takeover: frontify takeover detection POC ghost-takeover: ghost takeover detection POC gitbook-takeover: gitbook takeover detection POC helpjuice-takeover: helpjuice takeover detection POC helpscout-takeover: helpscout takeover detection