漏洞描述 Emerson XWEB 300D EVO是美国Emerson公司的一款节能空调。Emerson XWEB 300D EVO 3.0.7--3ee403存在目录遍历漏洞(CVE-2021-45427)。攻击者可能通过浏览目录结构,访问到某些隐秘文件包括配置文件、日志、源代码等,配合其它漏洞的综合利用,攻击者可以轻易的获取更高的权限。
相关漏洞推荐 POC CVE-2006-3392: Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure POC CVE-2011-3600: Apache OFBiz - XML External Entity Injection POC CVE-2015-8350: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS POC CVE-2016-15043: WP Mobile Detector <= 3.5 - Unrestricted File Upload POC CVE-2017-11107: phpLDAPadmin <= 1.2.3 - Reflected XSS POC CVE-2019-11253: Kubernetes API Server - YAML Parsing DoS (Billion Laughs) POC CVE-2019-15823: WPS Hide Login <= 1.5.2.2 - Login Page Bypass POC CVE-2019-9082: ThinkPHP < 3.2.4 - Remote Code Execution POC CVE-2020-12832: WordPress Simple File List - Path Traversal POC CVE-2020-13125: Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass POC CVE-2021-24213: GiveWP <= 2.9.7 - Cross-Site Scripting POC CVE-2021-3007: Laminas Project laminas-http - Remote Code Execution POC CVE-2021-33829: Drupal 7 CKEditor XSS