BOA Webserver 文件读取(CVE-2017-9833)

2023-01-29 BOA Webserver PoC No

Description

BOA Webserver 0.94.14rc21 中的 /cgi-bin/wapopen 允许使用 FILECAMERA 变量(由 GET发送)注入“../..”以读取具有 root 权限的文件。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities