漏洞描述 大华智能物联综合管理平台是一款集成多项业务管理功能的智能物联基础软件,广泛应用于智能园区和商业综合体等场景。该系统的 /ars/list 接口存在SQL注入漏洞,攻击者可以通过构造恶意请求执行任意SQL语句,可能导致敏感信息泄露或数据库被篡改。
相关漏洞推荐 大华智能物联综合管理平台 /evo-apigw/evo-cirs/file/download 文件读取漏洞 大华ICC智能物联综合管理平台 /evo-apigw/evo-cirs/material/viewPDF 文件读取漏洞 POC CVE-2017-7925: Dahua Security - Configuration File Disclosure POC CVE-2021-33044: Dahua IPC/VTH/VTO - Authentication Bypass POC CVE-2021-33045: Dahua IPC/VTH/VTO - Authentication Bypass POC CVE-2023-3836: Dahua Smart Park Management - Arbitrary File Upload POC CVE-2017-7925: Dahua Security - Configuration File Disclosure POC CVE-2021-33044: Dahua IPC/VTH/VTO devices Authentication Bypass POC CVE-2023-3836: Dahua Smart Park Management - Arbitrary File Upload POC dahua-dss-attachment-downloadatt-fileread: Dahua DSS Attachment Downloadatt Fileread POC dahua-eims-capture-handle-rce: Dahua EIMS capture_handle Remote Command Execution POC dahua-icc-readpic-fileread: Dahua Icc Readpic File Read POC CNVD-2017-06001: Dahua DSS - SQL Injection