漏洞描述 雄迈(Xiongmai),全称Hangzhou Xiongmai Technology Co.,Ltd.,是一家总部位于中国杭州的高科技公司。熊迈专注于视频监控产品的研发、制造和销售,并成为全球领先的视频监控设备供应商之一。 XiongMaiuc-httpd 具有目录遍历功能,允许通过“GET ../”HTTP 请求读取任意文件。
相关漏洞推荐 POC cl-te-http-smuggling: Basic CL.TE - HTTP request smuggling POC te-cl-http-smuggling: Basic TE.CL - HTTP Request Smuggling POC CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC CVE-2006-1681: Cherokee HTTPD <=0.5 - Cross-Site Scripting POC CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal POC CVE-2017-15715: Apache httpd <=2.4.29 - Arbitrary File Upload POC CVE-2018-16133: Cybrotech CyBroHttpServer 1.0.3 - Local File Inclusion POC CVE-2018-18778: ACME mini_httpd <1.30 - Local File Inclusion POC CVE-2019-10092: Apache HTTP Server <=2.4.39 - HTML Injection/Partial Cross-Site Scripting POC CVE-2019-10098: Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect POC CVE-2020-11984: Apache HTTP Server - Remote Code Execution POC CVE-2024-23334: aiohttp - Directory Traversal POC CVE-2024-23692: Rejetto HTTP File Server - Template injection